No account yet?
Home » Exploits » 6rbScript 'section.php' Local File Include Vulnerability
6rbScript 'section.php' Local File Include Vulnerability E-mail
Feeds - Exploits
Written by Stack   
Wednesday, 25 March 2009 22:41
6rbScript 'section.php' Local File Include Vulnerability


-\\Bugtraq ID:
31299

-\\Class:
Input Validation Error

-\\CVE:
CVE-2008-6453


-\\Remote:
Yes

-\\Local:
No

-\\Published:
Sep 22 2008 12:00AM

-\\Updated:
Mar 25 2009 08:46PM

-\\Credit:
Stack



-\\Vulnerable:
6rbScript 6rbScript  3.3
6rbScript 6rbScript  0



-\\Discussion
6rbScript is prone to a local file-include vulnerability because it fails to properly sanitize
user-supplied input.

An attacker can exploit this vulnerability using directory-traversal strings to view local
files within the context of the webserver process. Information harvested may aid in further attacks.

6rbScript 3.3 is vulnerable; other versions may also be affected.



-\\Exploit(s)/PoC(s):
Attackers can exploit this issue via a browser.

The following example URI is available:

http://www.example.com/section.php?name=../../../../etc/passwd



-\\Solution
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or
if you are aware of more recent information, please mail us at: This e-mail address is being protected from spambots. You need JavaScript enabled to view it .



-\\References(s)
--6rbScript Homepage
http://6rbscript.com  (6rbScript )
 

Security Services by HSC