fastpublish CMS config[fsBase] file include
| fastpublish-fsbase-file-include (26897) |
Description:
fastpublish CMS could allow a remote attacker to include malicious PHP files. A remote attacker could send a specially-crafted URL request to the drucken.php, drucken2.php, email_an_benutzer.php, rechnung.php, suche/search.php or adminbereich/admin.php script using the 'config[fsBase]' parameter to specify a malicious PHP file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable system.
Consequences:
Gain Access
Remedy:
No remedy available as of July 9, 2011.
References:
- fastpublish CMS Web site: Fastpublish Content Management System - Home.
- BID-18163: Fastpublish CMS Multiple Remote File Include Vulnerabilities
- CVE-2006-2726: PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files via the config[fsBase] parameter in (1) drucken.php, (2) drucken2.php, (3) email_an_benutzer.php, (4) rechnung.php, (5) suche/search.php and (6) adminbereich/admin.php.
- OSVDB ID: 26157: fastpublish CMS drucken.php config[fsBase] Variable Remote File Inclusion
- OSVDB ID: 26158: fastpublish CMS drucken2.php config[fsBase] Variable Remote File Inclusion
- OSVDB ID: 26159: fastpublish CMS email_an_benutzer.php config[fsBase] Variable Remote File Inclusion
- OSVDB ID: 26160: fastpublish CMS rechnung.php config[fsBase] Variable Remote File Inclusion
- OSVDB ID: 26161: fastpublish CMS suche/search.php config[fsBase] Variable Remote File Inclusion
- OSVDB ID: 26162: fastpublish CMS adminbereich/admin.php config[fsBase] Variable Remote File Inclusion
- SA20346: Fastpublish CMS "config[fsBase]" File Inclusion Vulnerabilities
- VUPEN/ADV-2006-2043: Fastpublish CMS config[fsBase] Parameter Remote File Inclusion Vulnerability
Platforms Affected:
- fastpublish fastpublish CMS 1.6.9.d
Reported:
May 29, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
