Exponent CMS Local File Include and Arbitrary File Upload Vulnerabilities
BID:47757
Info
Exponent CMS Local File Include and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 47757 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 09 2011 12:00AM |
| Updated: | May 09 2011 12:00AM |
| Credit: | AutoSec Tools |
| Vulnerable: |
Exponent Exponent CMS 2.0.0 beta 1.1 |
| Not Vulnerable: | |
Discussion
Exponent CMS Local File Include and Arbitrary File Upload Vulnerabilities
Exponent CMS is prone to a local file-include vulnerability and an arbitrary-file-upload vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver, and obtain sensitive information.
Exponent CMS 2.0.0 beta 1.1 is vulnerable; other versions may also be affected.
Exponent CMS is prone to a local file-include vulnerability and an arbitrary-file-upload vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver, and obtain sensitive information.
Exponent CMS 2.0.0 beta 1.1 is vulnerable; other versions may also be affected.
Exploit / POC
Exponent CMS Local File Include and Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URI and exploit are available:
http://www.example.com/exponent/content_selector.php?controller=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00&section=&action=
An attacker can exploit these issues through a browser.
The following example URI and exploit are available:
http://www.example.com/exponent/content_selector.php?controller=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00&section=&action=
Solution / Fix
Exponent CMS Local File Include and Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Exponent CMS Local File Include and Arbitrary File Upload Vulnerabilities
References:
References:
- Product Homepage (Exponent)