Noguska Nola Remote File Include Vulnerability
BID:5116
Info
Noguska Nola Remote File Include Vulnerability
| Bugtraq ID: | 5116 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2002 12:00AM |
| Updated: | Jun 27 2002 12:00AM |
| Credit: | Discovery credited to [email protected]. |
| Vulnerable: |
Noguska Nola 1.1.2 Noguska Nola 1.1.1 |
| Not Vulnerable: | |
Discussion
Noguska Nola Remote File Include Vulnerability
Noguska Nola is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers. If the remote file is a PHP script, this may allow for execution of attacker-supplied PHP code with the privileges of the webserver.
Noguska Nola is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers. If the remote file is a PHP script, this may allow for execution of attacker-supplied PHP code with the privileges of the webserver.
Exploit / POC
Noguska Nola Remote File Include Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Noguska Nola Remote File Include Vulnerability
Solution:
Reportedly, exploitation of this type of vulnerability is not possible unless both 'allow_url_fopen' and 'register_globals' are enabled in the local site PHP configuration.
It is good practice to disable any unneeded options.
The following patch was produced by Ryan Fox <[email protected]> to circumvent this vulnerability by defining disallowed file extensions:
diff -r nola/docmgmtadd.php nola.orig/docmgmtadd.php
120,130d119
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($file_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
diff -r nola/includes/defines.php nola.orig/includes/defines.php
301,303d300
< //disallowed file extentions
< $disallowedfileext=array('.php','.phps','.php3');
<
diff -r nola/invitemadd1.php nola.orig/invitemadd1.php
21,31d20
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($graphic_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
45,55d33
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($catalogsheet_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
diff -r nola/invitemupd.php nola.orig/invitemupd.php
27,37d26
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($graphic_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
51,61d39
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($catalogsheet_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
171c149
< <? include('includes/footer.php'); ?>
---
> <? include('includes/footer.php'); ?>
\ No newline at end of file
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reportedly, exploitation of this type of vulnerability is not possible unless both 'allow_url_fopen' and 'register_globals' are enabled in the local site PHP configuration.
It is good practice to disable any unneeded options.
The following patch was produced by Ryan Fox <[email protected]> to circumvent this vulnerability by defining disallowed file extensions:
diff -r nola/docmgmtadd.php nola.orig/docmgmtadd.php
120,130d119
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($file_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
diff -r nola/includes/defines.php nola.orig/includes/defines.php
301,303d300
< //disallowed file extentions
< $disallowedfileext=array('.php','.phps','.php3');
<
diff -r nola/invitemadd1.php nola.orig/invitemadd1.php
21,31d20
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($graphic_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
45,55d33
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($catalogsheet_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
diff -r nola/invitemupd.php nola.orig/invitemupd.php
27,37d26
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($graphic_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
51,61d39
< $nondisallowedfile=1;
< foreach($disallowedfileext as $this) {
< if ($substr_count($catalogsheet_name, $this)) {
< $nondisallowedfile=0;
< break;
< };
< };
<
< // illegal file type!
< if ($nondisallowedfile != 1) die(texterror('This file type is not supported.'));
<
171c149
< <? include('includes/footer.php'); ?>
---
> <? include('includes/footer.php'); ?>
\ No newline at end of file
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.