Commentics 'index.php' Arbitrary File Deletion Vulnerability
BID:54104
Info
Commentics 'index.php' Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 54104 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2012 12:00AM |
| Updated: | Jun 20 2012 12:00AM |
| Credit: | Jean Pascal Pereira |
| Vulnerable: |
Commentics Commentics 2.0 |
| Not Vulnerable: | |
Discussion
Commentics 'index.php' Arbitrary File Deletion Vulnerability
Commentics is prone to a vulnerability that lets attackers delete arbitrary files on an affected computer in the context of the web server.
Attackers can exploit this issue with directory-traversal strings ('../') to delete arbitrary files; this may aid in launching further attacks.
Commentics 2.0 is vulnerable; prior versions may also be affected.
Commentics is prone to a vulnerability that lets attackers delete arbitrary files on an affected computer in the context of the web server.
Attackers can exploit this issue with directory-traversal strings ('../') to delete arbitrary files; this may aid in launching further attacks.
Commentics 2.0 is vulnerable; prior versions may also be affected.
Exploit / POC
Commentics 'index.php' Arbitrary File Deletion Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/commentics/commentics/comments/[admin_path]/index.php?page=tool_db_backup&action=delete&id=../index.php
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/commentics/commentics/comments/[admin_path]/index.php?page=tool_db_backup&action=delete&id=../index.php
Solution / Fix
Commentics 'index.php' Arbitrary File Deletion Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Commentics 'index.php' Arbitrary File Deletion Vulnerability
References:
References:
- Commentics Homepage (commentics)
- Commentics 2.0 <= Multiple Vulnerabilities (Jean Pascal Pereira )