EspoCRM '/install/index.php' Remote File Include Vulnerability
BID:70809
Info
EspoCRM '/install/index.php' Remote File Include Vulnerability
| Bugtraq ID: | 70809 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7985 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2014 12:00AM |
| Updated: | Oct 29 2014 12:00AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
EspoCRM '/install/index.php' Remote File Include Vulnerability
EspoCRM is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary script code in the context of the web server process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
EspoCRM version 2.5.2 and prior are vulnerable.
EspoCRM is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary script code in the context of the web server process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
EspoCRM version 2.5.2 and prior are vulnerable.
Exploit / POC
EspoCRM '/install/index.php' Remote File Include Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com /install/index.php?installProcess=1&action=../../../../../../../../ tmp/file
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com /install/index.php?installProcess=1&action=../../../../../../../../ tmp/file
Solution / Fix
EspoCRM '/install/index.php' Remote File Include Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EspoCRM '/install/index.php' Remote File Include Vulnerability
References:
References: