Ravens PHP Scripts

Mambo Coppermine Component File Inclusion Vulnerability
Date: Thursday, August 17, 2006 @ 13:15:10 CDT
Topic: Security


TITLE: Mambo Coppermine Component File Inclusion Vulnerability

SECUNIA ADVISORY ID: SA21539

VERIFY ADVISORY: http://secunia.com/advisories/21539/

CRITICAL: Highly critical

IMPACT: System access

WHERE: >From remote

SOFTWARE: Coppermine 1.x (component for Mambo) -- http://secunia.com/product/11551/

DESCRIPTION: k1tk4t has discovered a vulnerability in the Coppermine component for Mambo, which can be exploited by malicious people to compromise a vulnerable system.

Input passed to the "mosConfig_absolute_path" parameter in components/com_cpg/cpg.php isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources. Successful exploitation requires that "register_globals" is enabled. The vulnerability has been confirmed in version 1.0. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly verified.
Set "register_globals" to "Off".

PROVIDED AND/OR DISCOVERED BY: k1tk4t

ORIGINAL ADVISORY: http://milw0rm.com/exploits/2196








This article comes from Ravens PHP Scripts
https://www.ravenphpscripts.com

The URL for this story is:
https://www.ravenphpscripts.com/modules.php?name=News&file=article&sid=2328