Xataface 'action' Parameter Local File Include Vulnerability
BID:48126
Info
Xataface 'action' Parameter Local File Include Vulnerability
| Bugtraq ID: | 48126 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2011 12:00AM |
| Updated: | Jul 04 2011 06:10PM |
| Credit: | ItSecTeam |
| Vulnerable: |
Xataface Xataface 1.3rc2 Xataface Xataface 1.3rc1 Xataface Xataface 1.2.5 Xataface Xataface 1.2 Xataface Xataface 1.1 Xataface Xataface 1.0 |
| Not Vulnerable: |
Xataface Xataface 1.2.6 |
Discussion
Xataface 'action' Parameter Local File Include Vulnerability
Xataface is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
NOTE (July 4, 2011): The vendor indicates that this issue affects versions prior to Xataface 1.2.6, while the reporter indicates 1.3rc1 and 1.3rc2 are affected.
Xataface is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
NOTE (July 4, 2011): The vendor indicates that this issue affects versions prior to Xataface 1.2.6, while the reporter indicates 1.3rc1 and 1.3rc2 are affected.
Exploit / POC
Xataface 'action' Parameter Local File Include Vulnerability
Attackers can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/index.php?-action=../../../../../../etc/passwd%00
Attackers can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/index.php?-action=../../../../../../etc/passwd%00