No account yet?
Home » Exploits » Scriptsez Easy Image Downloader 'main.php' Local File Include Vulnerability
Scriptsez Easy Image Downloader 'main.php' Local File Include Vulnerability E-mail
Feeds - Exploits
Written by JosS   
Wednesday, 18 February 2009 20:43
Scriptsez Easy Image Downloader 'main.php' Local File Include Vulnerability


-\\Bugtraq ID:
31695

-\\Class:
Input Validation Error

-\\CVE:
CVE-2008-6089


-\\Remote:
Yes

-\\Local:
No

-\\Published:
Oct 10 2008 12:00AM

-\\Updated:
Feb 18 2009 05:57PM

-\\Credit:
JosS



-\\Vulnerable:
ScriptsEZ.net Easy Image Downloader  0



-\\Discussion
Scriptsez Easy Image Downloader is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability using directory-traversal strings to view local files within the context of the webserver process. Information harvested may aid in further attacks.



-\\Exploit(s)/PoC(s):
Attackers can exploit this issue via a browser.

The following example URI is available:

http://www.example.com/main.php?action=download&id=../../../../../../../../../../../../../../../etc/passwd



-\\Solution
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: This e-mail address is being protected from spambots. You need JavaScript enabled to view it .



-\\References(s)
--Easy Image Downloader Homepage
http://www.scriptsez.net/?action=details&cat=Content%20Management&id=117265004  (Scriptez)

 

Security Services by HSC