InstantCMS 'index.php' Arbitrary PHP Code Execution Vulnerability
BID:60816
Info
InstantCMS 'index.php' Arbitrary PHP Code Execution Vulnerability
| Bugtraq ID: | 60816 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2013 12:00AM |
| Updated: | Jul 03 2013 08:51PM |
| Credit: | AkaStep |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
InstantCMS 'index.php' Arbitrary PHP Code Execution Vulnerability
InstantCMS is prone to an arbitrary PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
InstantCMS 1.6 and 1.7 are vulnerable; other versions may also be affected.
InstantCMS is prone to an arbitrary PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
InstantCMS 1.6 and 1.7 are vulnerable; other versions may also be affected.
Exploit / POC
InstantCMS 'index.php' Arbitrary PHP Code Execution Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?view=search&query=${echo phpinfo()}&look=allwords
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?view=search&query=${echo phpinfo()}&look=allwords
Solution / Fix
InstantCMS 'index.php' Arbitrary PHP Code Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
InstantCMS 'index.php' Arbitrary PHP Code Execution Vulnerability
References:
References: