e107 Image Gallery Plugin 'name' Parameter Remote File Disclosure Vulnerability
BID:54096
Info
e107 Image Gallery Plugin 'name' Parameter Remote File Disclosure Vulnerability
| Bugtraq ID: | 54096 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2012 12:00AM |
| Updated: | Jun 19 2012 12:00AM |
| Credit: | Sammy FORGIT |
| Vulnerable: |
e107 Image Gallery 0.9.7.1 |
| Not Vulnerable: | |
Discussion
e107 Image Gallery Plugin 'name' Parameter Remote File Disclosure Vulnerability
The Image Gallery Plugin for e107 is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Image Gallery 0.9.7.1 is vulnerable; other versions may also be affected.
The Image Gallery Plugin for e107 is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Image Gallery 0.9.7.1 is vulnerable; other versions may also be affected.
Exploit / POC
e107 Image Gallery Plugin 'name' Parameter Remote File Disclosure Vulnerability
Attackers can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/e107_plugins/image_gallery/viewImage.php?name=../../../../e107_config.php&type=album
Attackers can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/e107_plugins/image_gallery/viewImage.php?name=../../../../e107_config.php&type=album
Solution / Fix
e107 Image Gallery Plugin 'name' Parameter Remote File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
e107 Image Gallery Plugin 'name' Parameter Remote File Disclosure Vulnerability
References:
References: