newsPHP Remote File Include Vulnerability
BID:8488
Info
newsPHP Remote File Include Vulnerability
| Bugtraq ID: | 8488 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2003 12:00AM |
| Updated: | Aug 25 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Dariusz 'Officerrr' Kolasinski. |
| Vulnerable: |
newsPHP newsPHP 216 |
| Not Vulnerable: | |
Discussion
newsPHP Remote File Include Vulnerability
A file include vulnerability has been reported in the nphpd.php module of newsPHP that may permit an attacker to include and execute malicious script code on a vulnerable host.
The issue is reported to exist in the LangFile variable of nphpd.php module of the software. Successful exploitation may lead to execution of arbitrary code on a vulnerable system by a remote attacker.
A file include vulnerability has been reported in the nphpd.php module of newsPHP that may permit an attacker to include and execute malicious script code on a vulnerable host.
The issue is reported to exist in the LangFile variable of nphpd.php module of the software. Successful exploitation may lead to execution of arbitrary code on a vulnerable system by a remote attacker.
Exploit / POC
newsPHP Remote File Include Vulnerability
The following proof of concept was provided:
http://www.example.com/nphp/nphpd.php?nphp_config[LangFile]=/evil/file
The following proof of concept was provided:
http://www.example.com/nphp/nphpd.php?nphp_config[LangFile]=/evil/file
Solution / Fix
newsPHP Remote File Include Vulnerability
Solution:
It has been reported that the vendor has released a new version of newsPHP to address this and other issues. Please contact the vendor in order to obtain fixes.
Solution:
It has been reported that the vendor has released a new version of newsPHP to address this and other issues. Please contact the vendor in order to obtain fixes.
References
newsPHP Remote File Include Vulnerability
References:
References:
- newsPHP (newsPHP)
- newsPHP v216 patch (Dariusz 'Officerrr' Kolasinski
) - Re: XSS, Admin Access via Cookie and File Upload vulnerability in NewsPHP. ("Manuel Lopez"
)