Michael Dean Double Choco Latte Multiple Module Remote File Include Vulnerability
BID:9235
Info
Michael Dean Double Choco Latte Multiple Module Remote File Include Vulnerability
| Bugtraq ID: | 9235 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2003 12:00AM |
| Updated: | Dec 16 2003 12:00AM |
| Credit: | Announced by the vendor. |
| Vulnerable: |
Michael Dean Double Choco Latte 0.9.3 |
| Not Vulnerable: |
Michael Dean Double Choco Latte 0.9.4 |
Discussion
Michael Dean Double Choco Latte Multiple Module Remote File Include Vulnerability
It has been reported that Double Choco Latte may be prone to a file include vulnerability existing in mulitple modules. The problem exists in the 'login.php', 'logout.php', 'templates/static/frameset.php', 'templates/static/static.php', 'templates/tree/tree.php', 'templates/tree/frameset.php', 'setup/index.php', 'setup/default_records.inc.php', 'inc/config.php', 'inc/functions.inc.php', 'mssql.php', 'mysql.php', 'oracle8.php', 'pgsql.php', and 'sybase.php' scripts of the software.
Double Choco Latte version 0.9.3 is reported to be vulnerable to this issue, however other versions may be affected as well.
It has been reported that Double Choco Latte may be prone to a file include vulnerability existing in mulitple modules. The problem exists in the 'login.php', 'logout.php', 'templates/static/frameset.php', 'templates/static/static.php', 'templates/tree/tree.php', 'templates/tree/frameset.php', 'setup/index.php', 'setup/default_records.inc.php', 'inc/config.php', 'inc/functions.inc.php', 'mssql.php', 'mysql.php', 'oracle8.php', 'pgsql.php', and 'sybase.php' scripts of the software.
Double Choco Latte version 0.9.3 is reported to be vulnerable to this issue, however other versions may be affected as well.
Exploit / POC
Michael Dean Double Choco Latte Multiple Module Remote File Include Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Michael Dean Double Choco Latte Multiple Module Remote File Include Vulnerability
Solution:
The vendor has released Double Choco Latte version 0.9.4 to address this issue.
Michael Dean Double Choco Latte 0.9.3
Solution:
The vendor has released Double Choco Latte version 0.9.4 to address this issue.
Michael Dean Double Choco Latte 0.9.3
-
SourceForge dcl-0.9.4.tar.gz
http://prdownloads.sourceforge.net/dcl/dcl-0.9.4.tar.gz?download
References
Michael Dean Double Choco Latte Multiple Module Remote File Include Vulnerability
References:
References:
- Double Choco Latte (Freshmeat)