PHP-Nuke Web Mail Remote PHP Script Execution Vulnerability
BID:6399
Info
PHP-Nuke Web Mail Remote PHP Script Execution Vulnerability
| Bugtraq ID: | 6399 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2002 12:00AM |
| Updated: | Dec 16 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.0 |
| Not Vulnerable: | |
Discussion
PHP-Nuke Web Mail Remote PHP Script Execution Vulnerability
A vulnerability has been discovered in the PHP-Nuke Web Mail module. When a user opens an email that contains an attachment, the file will be put in a remotely accessible web directory. It has been reported that the vulnerable module fails to filter active content passed as attachments, thereby allowing a malicious PHP script to be stored in a web directory.
By accessing a PHP script located in the web directory, arbitrary PHP commands will be executed on the target server.
A vulnerability has been discovered in the PHP-Nuke Web Mail module. When a user opens an email that contains an attachment, the file will be put in a remotely accessible web directory. It has been reported that the vulnerable module fails to filter active content passed as attachments, thereby allowing a malicious PHP script to be stored in a web directory.
By accessing a PHP script located in the web directory, arbitrary PHP commands will be executed on the target server.
Exploit / POC
PHP-Nuke Web Mail Remote PHP Script Execution Vulnerability
Ulf Harnhammer has released an exploit for this vulnerability.
Ulf Harnhammer has released an exploit for this vulnerability.
Solution / Fix
PHP-Nuke Web Mail Remote PHP Script Execution Vulnerability
Solution:
An unofficial patch has been released by Ulf HarnHammer.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Francisco Burzi PHP-Nuke 6.0
Solution:
An unofficial patch has been released by Ulf HarnHammer.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Francisco Burzi PHP-Nuke 6.0
-
Ulf Harnhammer php-nuke_webmail.zip
http://downloads.securityfocus.com/vulnerabilities/patches/php-nuke_we bmail.zip