VoipNow 'screen' Parameter Local File Include Vulnerability
BID:59370
Info
VoipNow 'screen' Parameter Local File Include Vulnerability
| Bugtraq ID: | 59370 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 21 2013 12:00AM |
| Updated: | Apr 21 2013 12:00AM |
| Credit: | i-Hmx |
| Vulnerable: |
Rack-Soft VoipNow 2.0 |
| Not Vulnerable: |
Rack-Soft VoipNow 2.4 |
Discussion
VoipNow 'screen' Parameter Local File Include Vulnerability
VoipNow is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this vulnerability to view files and execute local scripts in the context of the web server process. This may aid in further attacks.
Versions prior to VoipNow 2.4 are vulnerable.
VoipNow is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this vulnerability to view files and execute local scripts in the context of the web server process. This may aid in further attacks.
Versions prior to VoipNow 2.4 are vulnerable.
Exploit / POC
VoipNow 'screen' Parameter Local File Include Vulnerability
An attacker can exploit the issue with a browser
The following example URI is available:
https://www.example.com/help/index.php?screen=../../../../../../../../etc/voipnow/voipnow.conf
An attacker can exploit the issue with a browser
The following example URI is available:
https://www.example.com/help/index.php?screen=../../../../../../../../etc/voipnow/voipnow.conf
Solution / Fix
VoipNow 'screen' Parameter Local File Include Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
VoipNow 'screen' Parameter Local File Include Vulnerability
References:
References:
- VoipNow Service Provider Edition Homepage (Rack-Soft)