singapore admin.class.php directory traversal
| singapore-adminclass-directory-traversal (18532) |
Description:
singapore is a freely available PHP-based image gallery program for Microsoft Windows and Unix-based platforms. Singapore version 0.9.10 running on Microsoft Internet Information Server (IIS) with PHP version 4.3.4 and 4.3.9 and running on Apache version 1.3.33 with PHP 4.3.9 could allow a remote authenticated attacker to traverse directories or delete files, caused by a vulnerability in the admin.class.php script. A remote authenticated attacker, with gallery deletion privileges, could send a specially-crafted request containing "dot dot" sequences (/../) to traverse directories and delete all files within the installation directory.
Platforms Affected:
- PHP, PHP 4.3.4
- PHP, PHP 4.3.9
- Tamlyn Rhodes, singapore 0.9.10
Remedy:
Upgrade to the latest version of singapore Image Gallery Web Application (0.9.11 or later), available from the SourceForge.net Web site. See References.
Consequences:
File Manipulation
References:
- BugTraq Mailing List, Thu Dec 16 2004 - 18:19:59 CST , [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities at http://archives.neohapsis.com/archives/bugtraq/2004-12/0211.html.
- SIG^2 Vulnerability Research Advisory, 16 Dec 2004, singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities at http://www.security.org.sg/vuln/singapore0910.html.
- SourceForge.net, Project: singapore: Summary at http://sourceforge.net/projects/singapore/.
- SourceForge.net, Project: singapore: File List at http://sourceforge.net/project/showfiles.php?group_id=77687.
- BID-11990: Singapore Image Gallery Multiple Remote Vulnerabilities
- CVE-2004-1407: Multiple directory traversal vulnerabilities in singapore Image Gallery Web Application 0.9.10 allow remote attackers to (1) read arbitrary files via the showThumb method for thumb.php, or (2) delete arbitrary files via admin.class.php.
Reported:
Dec 16, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
