Mambo Server 'content.html.php' Include File Bug Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1015258
|
|
SecurityTracker URL: http://securitytracker.com/id?1015258
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Nov 23 2005
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 4.5.2.3 and prior 4.5.x versoins
|
Description: A vulnerability was reported in Mambo Server. A remote user can execute arbitrary code on the target system.
The software does not properly validate user-supplied input. A remote user can supply a specially crafted URL to cause the target
system to include and execute arbitrary PHP code from a remote location. The PHP code, including operating system commands, will
run with the privileges of the target web service.
If register_globals is disabled, this vulnerability can be exploited.
This
vulnerability is being actively exploited.
peter MC tachatte reported this vulnerability.
|
Impact: A remote user can execute arbitrary PHP code and operating system commands on the target system with the privileges of the target web service.
|
Solution: The vendor has issued a code fix, available at:
http://forum.mamboserver.com/showthread.php?t=66154
Alternately, a security
patch (4523.security_fix.zip) is also available:
http://mamboforge.net/frs/?group_id=5
The fix will be included in the pending
version 4.5.3.
|
Vendor URL: news.mamboserver.com/index.php?option=com_content&task=view&id=2144&Itemid=2 (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 23 Nov 2005 13:41:00 -0500
Subject: Mambo vulnerability
|
http://news.mamboserver.com/index.php?option=com_content&task=view&id=2144&Itemid=2
|
|