about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Sonium Enterprise Adressbook <= 0.2 (folder) Include Vulnerability



2006-08-18 Sonium Enterprise Adressbook <= 0.2 (folder) Include Vulnerability
Rated as : High Risk

+--------------------------------------------------------------------
+
+ Sonium Enterprise Adressbook Version 0.2 (folder) RFI
+
+ Original advisory:
+
http://www.bb-pcsecurity.de/Websecurity/342/org/Sonium_Enterprise_Adressbook_Version_0.2_(folder)_RFI.htm
+
+--------------------------------------------------------------------
+
+ Affected Software .: Sonium Enterprise Adressbook Version 0.2
+ Venedor ...........: http://www.sonium-php.de
+ Class .............: Remote File Inclusion
+ Risk ..............: high (Remote File Execution)
+ Found by ..........: Philipp Niedziela
+ Contact ...........: webmaster[at]bb-pcsecurity[.]de
+
+--------------------------------------------------------------------
+
+ Affected Files:
+ /plugins/*.php (not config.php)
+
+ First lines of all these scripts:
+ .....
+     include("$folder/config.php");
+ .....
+
+--------------------------------------------------------------------
+
+ $folder is not properly sanitized before being used
+
+--------------------------------------------------------------------
+
+ Solution:
+ Deny direct access to all files in folder "plugins"
+ or modify code:
+
+ if(!isset($_REQUEST['folder']) && !isset($_GET['folder']) &&
!isset($_POST['folder'])){
+  //code of org. *.php
+ }
+ else {
+  echo "You cannot access this file directly.";
+  die();
+ }
+
+--------------------------------------------------------------------
+
+ PoC:
+
+ http://[target]/plugins/1_Adressbuch/delete.php?folder=[script]
+
+--------------------------------------------------------------------
+
+ Greets: /str0ke
+
+-------------------------[ E O F ]----------------------------------


securitydot.net - 2006-08-18

Advertising

Copyright 2007, SecurityDot
Mon, 09 Nov 2009 04:33:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
hotsexxxx mambo Remo papasmurf www.520ava openssh-3. www.india SimpleBoar Xxl big ti www.heyan1 News+Searc www.segou1 lo119l news for c www.seexxi Nayanthara ravi tripa apache 1.3 world sexc 200 /compo www.xsxsxs HI!__Order zeit das s 200 /compo inv WWW.TAKTAZ ravi tripa 200 /compo win invision Zeroboard- 110W.CN www.szpkub news for c mambo Remo taob8.com jnrn.diytr mambo Remo HI!__Order www.anopos www.520ava phonerotic www.oj88.c www.1918sf www.hfwww. www.gueizh Sex vedios php-nuke+2 www.szpkub TAMILActre www.51kanm