phpCollegeExchange Multiple Security Vulnerabilities
BID:43843
Info
phpCollegeExchange Multiple Security Vulnerabilities
| Bugtraq ID: | 43843 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2219 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2009 12:00AM |
| Updated: | Jun 23 2009 12:00AM |
| Credit: | CraCkEr |
| Vulnerable: |
phpCollegeExchange phpCollegeExchange 0.1.5c |
| Not Vulnerable: | |
Discussion
phpCollegeExchange Multiple Security Vulnerabilities
phpCollegeExchange is prone to a local file-include vulnerability, multiple remote file-include vulnerabilities, and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerability using directory-traversal strings to view and execute local files within the context of the webserver process. Information harvested may aid in further attacks.
The attacker can exploit the remote file-include vulnerabilities to obtain potentially sensitive information or to execute arbitrary script code in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
The attacker may exploit the cross-site scripting vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
phpCollegeExchange 0.1.5c is vulnerable; other versions may also be affected.
phpCollegeExchange is prone to a local file-include vulnerability, multiple remote file-include vulnerabilities, and multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerability using directory-traversal strings to view and execute local files within the context of the webserver process. Information harvested may aid in further attacks.
The attacker can exploit the remote file-include vulnerabilities to obtain potentially sensitive information or to execute arbitrary script code in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
The attacker may exploit the cross-site scripting vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
phpCollegeExchange 0.1.5c is vulnerable; other versions may also be affected.
Exploit / POC
phpCollegeExchange Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/i_head.php?home=[SHELL]
http://www.example.com/i_nav.php?home=[SHELL]
http://www.example.com/user_new_2.php?home=[SHELL]
http://www.example.com/books/allbooks.php?home=[SHELL]
http://www.example.com/books/home.php?home=[SHELL]
http://www.example.com/books/mybooks.php?home=[SHELL]
http://www.example.com/house/myrents.php?home=[LFI]
http://www.example.com/php pages/home.php?_SESSION[handle]=[XSS]
http://www.example.com/i_head.php?home=[XSS]
http://www.example.com/i_nav.php?home=[XSS]
http://www.example.com/books/allbooks.php?home=[XSS]
http://www.example.com/books/allbooks.php?_SESSION[handle]=[XSS]
http://www.example.com/books/home.php?home=[XSS]
http://www.example.com/books/home.php?_SESSION[handle]=[XSS]
http://www.example.com/books/i_nav.php?home=[XSS]
Attackers can exploit these issues through a browser. To exploit a cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/i_head.php?home=[SHELL]
http://www.example.com/i_nav.php?home=[SHELL]
http://www.example.com/user_new_2.php?home=[SHELL]
http://www.example.com/books/allbooks.php?home=[SHELL]
http://www.example.com/books/home.php?home=[SHELL]
http://www.example.com/books/mybooks.php?home=[SHELL]
http://www.example.com/house/myrents.php?home=[LFI]
http://www.example.com/php pages/home.php?_SESSION[handle]=[XSS]
http://www.example.com/i_head.php?home=[XSS]
http://www.example.com/i_nav.php?home=[XSS]
http://www.example.com/books/allbooks.php?home=[XSS]
http://www.example.com/books/allbooks.php?_SESSION[handle]=[XSS]
http://www.example.com/books/home.php?home=[XSS]
http://www.example.com/books/home.php?_SESSION[handle]=[XSS]
http://www.example.com/books/i_nav.php?home=[XSS]
Solution / Fix
phpCollegeExchange Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
phpCollegeExchange Multiple Security Vulnerabilities
References:
References:
- phpCollegeExchange Project Page (SourceForge)