漏洞信息详情
MCGalleryPRO ‘random2.php’PHP远程文件包含漏洞
- CNNVD编号:CNNVD-200609-168
- 危害等级: 高危
- CVE编号:
CVE-2006-4720
- 漏洞类型:
输入验证
- 发布时间:
2006-09-12
- 威胁类型:
远程
- 更新时间:
2006-09-13
- 厂 商:
mcgallery - 漏洞来源:
Solpot chris_hasib… -
漏洞简介
mcGalleryPRO是一款图片收藏管理程序
mcGalleryPRO的random2.php文件没有正确过滤对path_to_folder参数的输入,攻击者可以通过包含本地或外部资源的任意文件执行PHP代码。
random2.php中有漏洞的代码如下:
if (!empty($_SERVER)) { extract($_SERVER, EXTR_OVERWRITE); }
if (!empty($_GET)) { extract($_GET, EXTR_OVERWRITE); }
if (!empty($_POST)) { extract($_POST, EXTR_OVERWRITE); }
if (!empty($_COOKIE)) { extract($_COOKIE, EXTR_OVERWRITE); }
if (!empty($_SESSION)) { extract($_SESSION, EXTR_OVERWRITE); }
include (\”$path_to_folder/admin/common.php\”);
include (\”$path_to_folder/lang/$lang_def\”);
参考网址
来源: BID
名称: 19936
链接:http://www.securityfocus.com/bid/19936
来源: MISC
链接:http://www.nyubicrew.org/adv/solpot-adv-06.txt
来源: MILW0RM
名称: 2342
链接:http://www.milw0rm.com/exploits/2342
来源: VUPEN
名称: ADV-2006-3543
链接:http://www.frsirt.com/english/advisories/2006/3543
来源: SECUNIA
名称: 21850
链接:http://secunia.com/advisories/21850
来源: XF
名称: mcgallerypro-random2-file-include(28848)
链接:http://xforce.iss.net/xforce/xfdb/28848
来源: BUGTRAQ
名称: 20060910 SolpotCrew Advisory #8 – Mcgallerypro (path_to_folder) Remote File Inclusion
链接:http://www.securityfocus.com/archive/1/archive/1/445783/100/0/threaded
来源: SREASON
名称: 1556
链接:http://securityreason.com/securityalert/1556
来源: MILW0RM
名称: 2342