Software: Subscribe to Comments
Advisory report: https://security.dxw.com/advisories/admin-only-local-file-inclusion-and-arbitrary-code-execution-in-subscribe-to-comments-2-1-2/
CVE: Awaiting assignment
CVSS: 8 (High; AV:N/AC:L/Au:S/C:C/I:P/A:P)
Admin-only local file inclusion and arbitrary code execution in Subscribe to Comments 2.1.2
Administrators can perform Local File include attacks, which is a privilege escalation on systems where the administrator doesn?t have control over the server.
If administrators can upload PHP files (or any file which can contain ?<?php ??), they can also perform arbitrary code execution by the same method.
Proof of concept
Set ?Path to header? to ?/etc/passwd?
Check ?Use custom style for Subscription Manager?
Upgrade to version 2.3 or later
dxw believes in responsible disclosure. Your attention is drawn to our disclosure policy: https://security.dxw.com/disclosure/
Please contact us on email@example.com to acknowledge this report if you received it via a third party (for example, firstname.lastname@example.org) as they generally cannot communicate with us on your behalf.
This vulnerability will be published if we do not receive a response to this report with 14 days.
2015-07-13: Reported to vendor by email
2015-07-13: Requested CVE
2015-07-14: Vendor responded confirming fixed in version 2.3
Discovered by dxw:
Please visit security.dxw.com for more information.