SQuery Gaming Server Module "libpath" file include
| squery-file-include (25605) |
Description:
SQuery Gaming Server Module could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request to multiple scripts using the 'libpath' parameter to specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable system.
Note: This vulnerability also affects multiple vendor's game server related software that utilize the SQuery module, including Autonomous LAN Party (ALP).
Consequences:
Gain Access
Remedy:
Upgrade to the latest version of SQuery, available to registered users from the SQuery Web site. See References.
References:
- BugTraq Mailing List, Mon Jul 24 2006 - 13:14:14 CDT : SQuery v.x (devi.php) (armygame.php) Remote File Inclusion.
- BugTraq Mailing List, Sat Apr 01 2006 - 15:26:58 CST: SQuery <= 4.5 Remote File Inclusion Exploit.
- Bugtraq Mailing List, Sat Apr 08 2006 - 08:28:51 CDT: Autonomous LAN party File iNclusion.
- SQuery Web site: SQuery Gaming Server Module.
- BID-17434: SQuery LibPath Parameter Multiple Remote File Include Vulnerabilities
- CVE-2006-1610: PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter. NOTE: this only occurs when register_globals is disabled.
- CVE-2006-1688: Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory including (1) ase.php, (2) devi.php, (3) doom3.php, (4) et.php, (5) flashpoint.php, (6) gameSpy.php, (7) gameSpy2.php, (8) gore.php, (9) gsvari.php, (10) halo.php, (11) hlife.php, (12) hlife2.php, (13) igi2.php, (14) main.lib.php, (15) netpanzer.php, (16) old_hlife.php, (17) pkill.php, (18) q2a.php, (19) q3a.php, (20) qworld.php, (21) rene.php, (22) rvbshld.php, (23) savage.php, (24) simracer.php, (25) sof1.php, (26) sof2.php, (27) unreal.php, (28) ut2004.php, and (29) vietcong.php. NOTE: the lib/armygame.php vector is already covered by CV
- OSVDB ID: 24400: SQuery armygame.php libpath Variable Remote File Inclusion
- OSVDB ID: 24401: SQuery ase.php libpath Variable Remote File Inclusion
- OSVDB ID: 24402: SQuery devi.php libpath Variable Remote File Inclusion
- OSVDB ID: 24403: SQuery doom3.php libpath Variable Remote File Inclusion
- OSVDB ID: 24404: SQuery et.php libpath Variable Remote File Inclusion
- OSVDB ID: 24405: SQuery flashpoint.php libpath Variable Remote File Inclusion
- OSVDB ID: 24406: SQuery gameSpy.php libpath Variable Remote File Inclusion
- OSVDB ID: 24407: SQuery gameSpy2.php libpath Variable Remote File Inclusion
- OSVDB ID: 24408: SQuery gore.php libpath Variable Remote File Inclusion
- OSVDB ID: 24409: SQuery gsvari.php libpath Variable Remote File Inclusion
- OSVDB ID: 24410: SQuery halo.php libpath Variable Remote File Inclusion
- OSVDB ID: 24411: SQuery hlife.php libpath Variable Remote File Inclusion
- OSVDB ID: 24412: SQuery igi2.php libpath Variable Remote File Inclusion
- OSVDB ID: 24413: SQuery main.lib.php libpath Variable Remote File Inclusion
- OSVDB ID: 24414: SQuery hlife2.php libpath Variable Remote File Inclusion
- OSVDB ID: 24415: SQuery netpanzer.php libpath Variable Remote File Inclusion
- OSVDB ID: 24416: SQuery old_hlife.php libpath Variable Remote File Inclusion
- OSVDB ID: 24417: SQuery pkill.php libpath Variable Remote File Inclusion
- OSVDB ID: 24418: SQuery q2a.php libpath Variable Remote File Inclusion
- OSVDB ID: 24419: SQuery qworld.php libpath Variable Remote File Inclusion
- OSVDB ID: 24420: SQuery q3a.php libpath Variable Remote File Inclusion
- OSVDB ID: 24421: SQuery rene.php libpath Variable Remote File Inclusion
- OSVDB ID: 24422: SQuery rvbshld.php libpath Variable Remote File Inclusion
- OSVDB ID: 24423: SQuery savage.php libpath Variable Remote File Inclusion
- OSVDB ID: 24424: SQuery simracer.php libpath Variable Remote File Inclusion
- OSVDB ID: 24425: SQuery sof1.php libpath Variable Remote File Inclusion
- OSVDB ID: 24426: SQuery sof2.php libpath Variable Remote File Inclusion
- OSVDB ID: 24427: SQuery unreal.php libpath Variable Remote File Inclusion
- OSVDB ID: 24428: SQuery ut2004.php libpath Variable Remote File Inclusion
- OSVDB ID: 24429: SQuery vietcong.php libpath Variable Remote File Inclusion
- SA19482: SQuery "libpath" Multiple File Inclusion Vulnerabilities
- SA19588: Autonomous LAN Party File Inclusion Vulnerability
- SECTRACK ID: 1015884: Autonomous LAN Party Include File Bug Lets Remote Users Execute Arbitrary Code
- VUPEN/ADV-2006-1204: SQuery libpath Variable Handling Remote File Inclusion Vulnerabilities
- VUPEN/ADV-2006-1284: Autonomous LAN Party SQuery Module Remote File Inclusion Vulnerability
Platforms Affected:
- nerdclub.net Autonomous LAN Party (ALP) 0.98.1.0
- SQuery Project SQuery 4.5 and prior
Reported:
Apr 01, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
