Cedric Email Reader Skin Configuration Script Remote File Include Vulnerability
BID:6818
Info
Cedric Email Reader Skin Configuration Script Remote File Include Vulnerability
| Bugtraq ID: | 6818 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2003 12:00AM |
| Updated: | Feb 09 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to: MGhz <[email protected]> |
| Vulnerable: |
ISOCA Cedric email reader 0.3 ISOCA Cedric email reader 0.2 |
| Not Vulnerable: | |
Discussion
Cedric Email Reader Skin Configuration Script Remote File Include Vulnerability
It has been reported that Cedric Email Reader is prone to an issue that may allow remote attackers to include malicious files located on remote servers. This issue is present in the 'email.php' script.
Under some circumstances, it is possible for remote attackers to influence the include path for a configuration file to point to an external file on a remote server.
If the remote file is a malicious PHP script, this may be exploited to execute arbitrary system commands in the context of the web server.
It has also been reported that it is possible to cause local files to be included, resulting in disclosure of webserver readable files to the attacker. This has not been confirmed.
It has been reported that Cedric Email Reader is prone to an issue that may allow remote attackers to include malicious files located on remote servers. This issue is present in the 'email.php' script.
Under some circumstances, it is possible for remote attackers to influence the include path for a configuration file to point to an external file on a remote server.
If the remote file is a malicious PHP script, this may be exploited to execute arbitrary system commands in the context of the web server.
It has also been reported that it is possible to cause local files to be included, resulting in disclosure of webserver readable files to the attacker. This has not been confirmed.
Solution / Fix
Cedric Email Reader Skin Configuration Script Remote File Include Vulnerability
Solution:
It has been speculated that this vulnerability has been fixed in Cedric Email Reader version 0.4. This, however, has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been speculated that this vulnerability has been fixed in Cedric Email Reader version 0.4. This, however, has not been confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cedric Email Reader Skin Configuration Script Remote File Include Vulnerability
References:
References:
- Cedric Email Reader homepage (ISOCA)
- Cedric Email Reader (PHP) (MGhz
)