No account yet?
Home » Exploits » PassWiki 'site_id' Parameter Local File Include Vulnerability
PassWiki 'site_id' Parameter Local File Include Vulnerability E-mail
Feeds - Exploits
Written by mozi2weed@yahoo.com   
Friday, 13 March 2009 23:56
PassWiki 'site_id' Parameter Local File Include Vulnerability


-\\Bugtraq ID:
29455

-\\Class:
Input Validation Error

-\\CVE:
CVE-2008-6423


-\\Remote:
Yes

-\\Local:
No

-\\Published:
May 31 2008 12:00AM

-\\Updated:
Mar 13 2009 07:36PM

-\\Credit:
This e-mail address is being protected from spambots. You need JavaScript enabled to view it



-\\Vulnerable:
Momose PassWiki 0.9.17
Momose PassWiki 0.9.16 RC3



-\\Discussion
PassWiki is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.

Exploiting this issue allows remote attackers to view local files within the context of the webserver process.

PassWiki 0.9.17 and prior versions are vulnerable.



-\\Exploit(s)/PoC(s):
Attackers can exploit this issue using a browser.

The following example URI is available:

http://www.example.com/passwiki/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00



-\\Solution
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: This e-mail address is being protected from spambots. You need JavaScript enabled to view it .



-\\References(s)
--PassWiki Homepage
http://www.i-apps.net/passwiki  (Momose)
--PassWiki 0.9.17 download page
http://www.i-apps.net/passwiki/index.php?site_id=&page=%E3%83%80%E3%82%A6%E3%83%B3%E3%83%AD%E3%83%BC%E3%83%8  (Momose)
 

Security Services by HSC