AjaXplorer 'class.AJXP_ClientDriver.php' Multiple Local File Include Vulnerabilities
BID:52298
Info
AjaXplorer 'class.AJXP_ClientDriver.php' Multiple Local File Include Vulnerabilities
| Bugtraq ID: | 52298 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-1839 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2012 12:00AM |
| Updated: | Mar 08 2015 04:04PM |
| Credit: | Vendor reported this issue. |
| Vulnerable: |
AjaXplorer AjaXplorer 4.0.3 AjaXplorer AjaXplorer 3.2.4 |
| Not Vulnerable: |
AjaXplorer AjaXplorer 4.0.4 AjaXplorer AjaXplorer 3.2.5 |
Discussion
AjaXplorer 'class.AJXP_ClientDriver.php' Multiple Local File Include Vulnerabilities
AjaXplorer is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to obtain potentially sensitive information and execute arbitrary local scripts in the context of the Web server process. This could allow the attacker to compromise the application and the computer; other attacks are also possible.
AjaXplorer versions 3.2.4 and 4.0.3 are vulnerable; other versions may also be affected.
AjaXplorer is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to obtain potentially sensitive information and execute arbitrary local scripts in the context of the Web server process. This could allow the attacker to compromise the application and the computer; other attacks are also possible.
AjaXplorer versions 3.2.4 and 4.0.3 are vulnerable; other versions may also be affected.
Exploit / POC
AjaXplorer 'class.AJXP_ClientDriver.php' Multiple Local File Include Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
AjaXplorer 'class.AJXP_ClientDriver.php' Multiple Local File Include Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
AjaXplorer 'class.AJXP_ClientDriver.php' Multiple Local File Include Vulnerabilities
References:
References:
- AjaXplorer Homepage (AjaXplorer)
- Important Security Upgrade : AjaXplorer 4.0.4 & 3.2.5 (AjaXplorer )