PikaCMS Multiple Local File Disclosure Vulnerabilities
BID:48068
Info
PikaCMS Multiple Local File Disclosure Vulnerabilities
| Bugtraq ID: | 48068 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2011 12:00AM |
| Updated: | Jun 01 2011 12:00AM |
| Credit: | KnocKout |
| Vulnerable: |
PikaCMS PikaCMS 0 |
| Not Vulnerable: | |
Discussion
PikaCMS Multiple Local File Disclosure Vulnerabilities
PikaCMS is prone to multiple local file-disclosure vulnerabilities because it fails to adequately validate user-supplied input.
Exploiting these vulnerabilities may allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
PikaCMS is prone to multiple local file-disclosure vulnerabilities because it fails to adequately validate user-supplied input.
Exploiting these vulnerabilities may allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Exploit / POC
PikaCMS Multiple Local File Disclosure Vulnerabilities
Attackers can exploit these issues through a browser.
The following example URI is available:
http://www.example.com/gabime/showSource.php?file=../../../../../etc/passwd
The following exploit is available:
Attackers can exploit these issues through a browser.
The following example URI is available:
http://www.example.com/gabime/showSource.php?file=../../../../../etc/passwd
The following exploit is available:
Solution / Fix
PikaCMS Multiple Local File Disclosure Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].