Zimplit CMS Local File Include and Arbitrary File Upload Vulnerabilities
BID:53990
Info
Zimplit CMS Local File Include and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 53990 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2012 12:00AM |
| Updated: | Jun 17 2012 12:03AM |
| Credit: | KedAns-Dz |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Zimplit CMS Local File Include and Arbitrary File Upload Vulnerabilities
Zimplit CMS is prone to multiple local file-include vulnerabilities and an arbitrary file-upload vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the web server, execute arbitrary local files within the context of the web server, and obtain sensitive information.
Zimplit CMS 3.0 is vulnerable; other versions may also be affected.
Zimplit CMS is prone to multiple local file-include vulnerabilities and an arbitrary file-upload vulnerability.
An attacker can exploit these issues to upload arbitrary files onto the web server, execute arbitrary local files within the context of the web server, and obtain sensitive information.
Zimplit CMS 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Zimplit CMS Local File Include and Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues through a browser.
The following example inputs are available:
An attacker can exploit these issues through a browser.
The following example inputs are available:
Solution / Fix
Zimplit CMS Local File Include and Arbitrary File Upload Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Zimplit CMS Local File Include and Arbitrary File Upload Vulnerabilities
References:
References:
- Zimplit CMS Homepage (Zimplit)