Docebo multiple parameters file include

docebo-multiple-file-include (26633) The risk level is classified as MediumMedium Risk

Description:

Multiple Docebo modules could allow a remote attacker to include arbitrary remote files. If register_globals is enabled, a remote attacker could send a specially-crafted URL request to multiple scripts using the 'GLOBALS[where_framework]', 'GLOBALS[where_cms]', 'GLOBALS[where_lms]', 'GLOBALS[where_upgrade]', 'BBC_LANGUAGE_PATH' or 'BBC_LIB_PATH' parameter to specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable system.


Consequences:

Gain Access

Remedy:

Upgrade to the latest version of Docebo (3.5.0.3 or later), available from the DoceboCMS Web site. See References.

References:

  • BugTraq Mailing List, Fri Jun 09 2006 - 00:11:19 CDT : Docebo Kms 3.0.3, Remote command execution.
  • BugTraq Mailing List, Fri Jun 09 2006 - 00:31:46 CDT : Docebo Lms 3.0.3, Remote command execution.
  • BugTraq Mailing List, Thu Jun 08 2006 - 23:52:47 CDT : Docebo Core 3.0.3, Remote command execution.
  • DoceboCMS Web site: DoceboCMS.
  • Full-Disclosure Mailing List, Thu Jun 08 2006 - 23:23:02 CDT: Docebo CMS 3.0.3, Remote command execution.
  • BID-18109: Multiple Docebo Products Multiple Remote File Include Vulnerabilities
  • CVE-2006-2576: Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) lib.simplesel.php, (b) lib.filelist.php, (c) tree.documents.php, (d) lib.repo.php, and (e) lib.php, and (2) GLOBALS[where_scs] to (f) lib.teleskill.php. NOTE: this issue might be resultant from a global overwrite vulnerability.
  • CVE-2006-2577: Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) where_cms, (2) where_lms, (3) where_upgrade, (4) BBC_LIB_PATH, and (5) BBC_LANGUAGE_PATH parameters in various unspecifed scripts. NOTE: the provenance of some of this information is unknown; the details are obtained solely from third party information.
  • CVE-2006-3107: Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) admin/modules/news/news_class.php and (b) admin/modules/content/content_class.php, and (2) GLOBALS[where_cms] to (c) admin/modules/block_media/util.media.php. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576, but the vectors are different.
  • CVE-2006-6957: PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_framework] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576 and CVE-2006-3107, but the vectors are different.
  • CVE-2006-6963: Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_lms] parameter to (1) class.module/class.definition.php and (2) modules/scorm/scorm_utils.php. NOTE: this issue may overlap CVE-2006-2577.
  • OSVDB ID: 25757: Docebo Multiple Script Global Parameter Remote File Inclusion
  • OSVDB ID: 26707: Docebo CMS news_class.php GLOBALS[where_framework] Parameter Remote File Inclusion
  • OSVDB ID: 26708: Docebo CMS content_class.php GLOBALS[where_framework] Parameter Remote File Inclusion
  • OSVDB ID: 26709: Docebo CMS util.media.php GLOBALS[where_cms] Parameter Remote File Inclusion
  • OSVDB ID: 26710: Docebo CMS body.php GLOBALS[where_framework] Parameter Remote File Inclusion
  • OSVDB ID: 26711: Docebo CMS lib.php GLOBALS[where_framework] Parameter Remote File Inclusion
  • OSVDB ID: 26712: Docebo CMS class.definition.php GLOBALS[where_lms] Parameter Remote File Inclusion
  • OSVDB ID: 26713: Docebo CMS scorm_utils.php GLOBALS[where_lms] Parameter Remote File Inclusion
  • SA20260: Docebo Multiple File Inclusion Vulnerabilities
  • SECTRACK ID: 1016259: Docebo Include File Flaw in GLOBALS[`where_framework`] and GLOBALS[`where_cms`] Parameters Let Remote Users Execute Arbitrary Code
  • VUPEN/ADV-2006-1935: Docebo Multiple Parameter Handling Remote File Inclusion Vulnerabilities

Platforms Affected:

  • Docebo Docebo 3.0.3 and prior

Reported:

May 23, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email ignore thisxforceignore this@ignore thisus.ignore thisibm.comignore this

Return to the main page