SecurityAlert : 3911 CVE : CVE-2008-2482 CWE : CWE-22 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Victim interaction required : No Exploit Given : Yes Credit : Digital Security Research Group Published : 29.05.2008
Affected Software :
Insanevisions, Onecms, 2.5
Advisory Text :
Digital Security Research Group [DSecRG] Advisory #DSECRG-08-025
Application: OneCMS
Versions Affected: 2.5
Vendor URL: http://www.insanevisions.com/
Bug: Local File Include
Exploits: YES
Reported: 26.03.2008
Vendor Response: NONE
Solution: NONE
Date of Public Advisory: 23.05.2008
Author: Digital Security Research Group [DSecRG]
(research [at] dsec [dot] ru)
Description
***********
Local File Include vulnerability found in script install_mod.php
if (!is_numeric($mod)) { // makes sure that the user isnt entering a #
if ($filetype == "php") {
if ($_GET['act'] == "") {
echo "Are you sure you would like to install the <b>".$file."</b>
module?<br><a href='install_mod.php?load=".$mod."&act=go'>Yes</a>";
}
if ($_GET['act'] == "go") {
include ($file2);
...
Digital Security is leading IT security company in Russia, providing
information security consulting, audit and penetration testing services,
risk analysis and ISMS-related services and certification for ISO/IEC
27001:2005 and PCI DSS standards. Digital Security Research Group focuses
on web application and database security problems with vulnerability
reports, advisories and whitepapers posted regularly on our website.
Contact: research [at] dsec [dot] ru
http://www.dsec.ru (in Russian)
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.