XOOPS 'imagemanager.php' Local File Include Vulnerability
BID:47418
Info
XOOPS 'imagemanager.php' Local File Include Vulnerability
| Bugtraq ID: | 47418 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2011 12:00AM |
| Updated: | Apr 18 2011 12:00AM |
| Credit: | KedAns-Dz |
| Vulnerable: |
Xoops Xoops 2.5 |
| Not Vulnerable: | |
Discussion
XOOPS 'imagemanager.php' Local File Include Vulnerability
XOOPS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view arbitrary local files within the context of the webserver process. Successfully exploiting this issue may lead to other attacks.
XOOPS 2.5.0 is vulnerable; other versions may also be affected.
XOOPS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view arbitrary local files within the context of the webserver process. Successfully exploiting this issue may lead to other attacks.
XOOPS 2.5.0 is vulnerable; other versions may also be affected.
Exploit / POC
XOOPS 'imagemanager.php' Local File Include Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/[path]/imagemanager.php?target=/../../../../../../../../boot.ini%00&op=upload
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/[path]/imagemanager.php?target=/../../../../../../../../boot.ini%00&op=upload
Solution / Fix
XOOPS 'imagemanager.php' Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].