phpProfiles Multiple File Inclusion Vulnerabilities

Posted on Wednesday, December 20, 2006 @ 15:55:22 CST in Security
by Raven

SECUNIA ADVISORY ID: SA23423

VERIFY ADVISORY: http://secunia.com/advisories/23423/

CRITICAL: Highly critical

IMPACT: System access

SOFTWARE: phpProfiles 3.x - http://secunia.com/product/12934/

DESCRIPTION: nuffsaid has discovered several vulnerabilities in phpProfiles, which can be exploited by malicious people to compromise vulnerable systems. The vulnerabilities are confirmed in version 3.1.2. Other versions may also be affected.


Input passed to the "incpath" parameter in account.inc.php, admin_newcomm.inc.php, body_admin.inc.php, body.inc.php, comm_post.inc.php, commrecc.inc.php, do_reg.inc.php, friends.inc.php, header_admin.inc.php, header.inc.php, index.inc.php, menu_u.inc.php, menu_v.inc.php and notify.inc.php, the "menu" parameter in body_admin.inc.php and body.inc.php and the "scriptpath" parameter with the POST method to remove_pic.inc.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources. All scripts are located in the include directory.

SOLUTION:
Edit the source code to ensure that input is properly verified.
Use another product.

PROVIDED AND/OR DISCOVERED BY: nuffsaid

ORIGINAL ADVISORY: http://www.milw0rm.com/exploits/2956