Twenty Year Anniversary

Philex CMS 0.2 Directory Traversal

Philex CMS 0.2 Directory Traversal
Posted Aug 16, 2017
Authored by Renzi

Philex CMS version 0.2 suffers from a directory traversal vulnerability.

tags | exploit, file inclusion
MD5 | 2506b9c0aa524dc31cfbd3aa844da9b1

Philex CMS 0.2 Directory Traversal

Change Mirror Download
Title:
=======
Philex CMS - Directory Traversal

Introduction:
==============
A content management system (CMS) is a computer application that supports the creation and modification of digital content.
It is often used to support multiple users working in a collaborative environment.
CMS features vary widely. Most CMSs include Web-based publishing, format management, history editing and version control, indexing, search, and retrieval.
By their nature, content management systems support the separation of content and presentation.

Vulnerability Disclosure:
==========================
2017-08-15: Public Disclosure

Affected Product(s):
=====================
Philex 0.2

Exploitation Technique:
========================
Remote

Severity Level:
================
High

Technical Details & Description:
=================================
A Directory Traversal vulnerability has been discovered in the CMS Philex 0.2 CMS web-application.
The vulnerability is located in the 'cat' parameter of the`index.php` action GET method request.

Request Method(s):
[+] GET

Vulnerable Function(s):
[+] index.php

Vulnerable Parameter(s):
[+] cat

Proof of Concept (PoC):
========================
A path traversal attack (also known as directory traversal) aims to access files and directories that are stored outside the web root folder.
By manipulating variables that reference files with adot-dot-slash (../)a sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files.
It should be noted that access to files is limited by system operational access control.
This attack is also known as adot-dot-slasha, adirectory traversala, adirectory climbinga and abacktrackinga. [OWASP]

[+] http://www.uphighstore.com.br/index.php?cat=../etc/passwd

Solution
=========
There are several measures that enterprises can take to prevent directory traversal attacks and vulnerabilities.
For starters, programmers should be trained to validate user input from browsers.
Input validation ensures that attackers cannot use commands that leave the root directory or violate other access privileges.
Beyond this, filters can be used to block certain user input.
Enterprises typically employ filters to block URLs containing commands and escape codes that are commonly used by attackers.
Additionally, web server software (and any software that is used) should be kept up-to-date with current patches.
Regularly patching software is a critical practice for reducing security risk, as software patches typically contain security fixes. [Veracode]

Credits
========
Felipe "Renzi" Gabriel

Contact
========
renzi@linuxmail.org

References
==========
https://www.owasp.org/index.php/Path_Traversal
https://www.veracode.com/security/directory-traversal
https://en.wikipedia.org/wiki/Content_management_system

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

August 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    19 Files
  • 2
    Aug 2nd
    17 Files
  • 3
    Aug 3rd
    16 Files
  • 4
    Aug 4th
    1 Files
  • 5
    Aug 5th
    1 Files
  • 6
    Aug 6th
    19 Files
  • 7
    Aug 7th
    15 Files
  • 8
    Aug 8th
    9 Files
  • 9
    Aug 9th
    7 Files
  • 10
    Aug 10th
    10 Files
  • 11
    Aug 11th
    1 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    14 Files
  • 14
    Aug 14th
    18 Files
  • 15
    Aug 15th
    38 Files
  • 16
    Aug 16th
    16 Files
  • 17
    Aug 17th
    22 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close