Mambo Coppermine Component File Inclusion Vulnerability

Posted on Thursday, August 17, 2006 @ 13:15:10 CDT in Security
by Raven

TITLE: Mambo Coppermine Component File Inclusion Vulnerability

SECUNIA ADVISORY ID: SA21539

VERIFY ADVISORY: http://secunia.com/advisories/21539/

CRITICAL: Highly critical

IMPACT: System access

WHERE: >From remote

SOFTWARE: Coppermine 1.x (component for Mambo) -- http://secunia.com/product/11551/

DESCRIPTION: k1tk4t has discovered a vulnerability in the Coppermine component for Mambo, which can be exploited by malicious people to compromise a vulnerable system.

Input passed to the "mosConfig_absolute_path" parameter in components/com_cpg/cpg.php isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources. Successful exploitation requires that "register_globals" is enabled. The vulnerability has been confirmed in version 1.0. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly verified.
Set "register_globals" to "Off".

PROVIDED AND/OR DISCOVERED BY: k1tk4t

ORIGINAL ADVISORY: http://milw0rm.com/exploits/2196
 
 
click Related        click Share
 
 

Re: Mambo Coppermine Component File Inclusion Vulnerability (Score: 1)
by hitwalker on Thursday, August 17, 2006 @ 17:11:19 CDT
  
(User Info | Send a Message)

im not suprised.....
but who is using this...?
c'mon....speakup....lol

 
News ©

Site Info

Last SeenLast Seen
  • kguske
  • nextgen
Server TrafficServer Traffic
  • Total: 504,394,208
  • Today: 64,488
Server InfoServer Info
  • Mar 12, 2025
  • 07:02 am CDT