MidiCMS Website Builder Local File Include and Arbitrary File Upload Vulnerabilities
BID:47970
Info
MidiCMS Website Builder Local File Include and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 47970 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2011 12:00AM |
| Updated: | May 25 2011 12:00AM |
| Credit: | KedAns-Dz |
| Vulnerable: |
MidiCMS Software MidiCMS Website Builder 2011 |
| Not Vulnerable: | |
Discussion
MidiCMS Website Builder Local File Include and Arbitrary File Upload Vulnerabilities
MidiCMS Website Builder is prone to a local file-include vulnerability and an arbitrary-file-upload vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver, and obtain sensitive information.
MidiCMS Website Builder 2011 is vulnerable; other versions may also be affected.
MidiCMS Website Builder is prone to a local file-include vulnerability and an arbitrary-file-upload vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver, and obtain sensitive information.
MidiCMS Website Builder 2011 is vulnerable; other versions may also be affected.
Exploit / POC
MidiCMS Website Builder Local File Include and Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URIs are available:
http://www.example.com/admin/jscripts/tiny_mce/plugins/ezfilemanager/index.php
http://www.example.com/?html=../../../../../../../../../../boot.ini%00
An attacker can exploit these issues through a browser.
The following example URIs are available:
http://www.example.com/admin/jscripts/tiny_mce/plugins/ezfilemanager/index.php
http://www.example.com/?html=../../../../../../../../../../boot.ini%00
Solution / Fix
MidiCMS Website Builder Local File Include and Arbitrary File Upload Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MidiCMS Website Builder Local File Include and Arbitrary File Upload Vulnerabilities
References:
References:
- MidiCMS Website Builder Homepage (MidiCMS Website Builder)