|
Feeds -
Exploits
|
|
Written by mozi2weed@yahoo.com
|
|
Friday, 13 March 2009 23:56 |
PassWiki 'site_id' Parameter Local File Include Vulnerability
-\\Bugtraq ID: 29455
-\\Class: Input Validation Error
-\\CVE: CVE-2008-6423
-\\Remote: Yes
-\\Local: No
-\\Published: May 31 2008 12:00AM
-\\Updated: Mar 13 2009 07:36PM
-\\Credit:
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
-\\Vulnerable: Momose PassWiki 0.9.17 Momose PassWiki 0.9.16 RC3
-\\Discussion PassWiki is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue allows remote attackers to view local files within the context of the webserver process.
PassWiki 0.9.17 and prior versions are vulnerable.
-\\Exploit(s)/PoC(s): Attackers can exploit this issue using a browser.
The following example URI is available:
http://www.example.com/passwiki/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00
-\\Solution Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at:
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
.
-\\References(s) --PassWiki Homepage http://www.i-apps.net/passwiki (Momose) --PassWiki 0.9.17 download page http://www.i-apps.net/passwiki/index.php?site_id=&page=%E3%83%80%E3%82%A6%E3%83%B3%E3%83%AD%E3%83%BC%E3%83%8 (Momose)
|