CMS Lokomedia 'downlot.php' Arbitrary File Download Vulnerability
BID:46915
Info
CMS Lokomedia 'downlot.php' Arbitrary File Download Vulnerability
| Bugtraq ID: | 46915 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2011 12:00AM |
| Updated: | Mar 18 2011 12:00AM |
| Credit: | Xr0b0t |
| Vulnerable: |
bukulokomedia.com CMS Lokomedia 0 |
| Not Vulnerable: | |
Discussion
CMS Lokomedia 'downlot.php' Arbitrary File Download Vulnerability
CMS Lokomedia is prone to a vulnerability that lets attackers download arbitrary files. This issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
CMS Lokomedia is prone to a vulnerability that lets attackers download arbitrary files. This issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
Exploit / POC
CMS Lokomedia 'downlot.php' Arbitrary File Download Vulnerability
An attacker can exploit this issue using a browser.
The following example URI is available:
http://www.example.com/[path]/downlot.php?file=../config/koneksi.php
An attacker can exploit this issue using a browser.
The following example URI is available:
http://www.example.com/[path]/downlot.php?file=../config/koneksi.php
Solution / Fix
CMS Lokomedia 'downlot.php' Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CMS Lokomedia 'downlot.php' Arbitrary File Download Vulnerability
References:
References:
- Vendor Homepage (bukulokomedia.com)