Multiple Comdev modules path[docroot] file include
| comdev-include-file-include (29220) |
Description:
Multiple Comdev modules could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request to the include.php or adminfoot.php script using the path[docroot] parameter to specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable Web server.
*CVSS:
| Base Score: | 7 |
| Access Vector: | Remote |
| Access Complexity: | Low |
| Authentication: | Not Required |
| Confidentiality Impact: | Partial |
| Integrity Impact: | Partial |
| Availability Impact: | Partial |
| Temporal Score: | 5.7 |
| Exploitability: | Unproven |
| Remediation Level: | Unavailable |
| Report Confidence: | Uncorroborated |
Consequences:
Gain Access
Remedy:
No remedy available as of July 9, 2011.
References:
- BugTraq Mailing List, Wed Sep 27 2006 - 13:27:35 CDT : Comdev CSV Importer 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 13:56:43 CDT : Comdev Links Directory 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 13:58:36 CDT : Comdev Guestbook 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:02:22 CDT : Comdev eCommerce 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:02:55 CDT : Comdev FAQ Support 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:04:14 CDT : Comdev Customer Helpdesk 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:04:41 CDT : Comdev Newsletter 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:04:53 CDT : Comdev Photo Gallery 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:05:03 CDT : Comdev News Publisher 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:05:12 CDT : Comdev Vote Caster 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:06:19 CDT : Comdev Web Blogger 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:06:35 CDT : Comdev Events Calendar 3.1 :) <= Remote File Inclusion.
- BugTraq Mailing List, Wed Sep 27 2006 - 14:06:53 CDT : Comdev Contact Form 3.1 :) <= Remote File Inclusion.
- Comdev Web site: More PHP Modules For Your Website.
- BID-20566: Multiple Comdev Applications Adminfoot.PHP Remote File Include Vulnerability
- CVE-2006-5101: PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher 3.1, (8) Comdev Newsletter 3.1, (9) Comdev Photo Gallery 3.1, (10) Comdev Vote Caster 3.1, (11) Comdev Web Blogger 3.1, and (12) Comdev eCommerce 3.1, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: it has been reported that 4.1 versions might also be affected.
- CVE-2006-5438: PHP remote file inclusion vulnerability in adminfoot.php in Comdev Forum 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
- CVE-2006-5439: PHP remote file inclusion vulnerability in adminfoot.php in Comdev Misc Tools 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
- CVE-2006-5440: PHP remote file inclusion vulnerability in adminfoot.php in Comdev Form Designer 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
- CVE-2006-5441: PHP remote file inclusion vulnerability in adminfoot.php in Comdev Web Blogger 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
- OSVDB ID: 29299: Comdev FAQ Support include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29300: Comdev Events Calendar include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29301: Comdev Photo Gallery include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29302: Comdev News Publisher include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29303: Comdev Web Blogger include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29304: Comdev CSV Importer include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29305: Comdev Guestbook include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29306: Comdev Links Directory include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29307: Comdev eCommerce include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29308: Comdev Customer Helpdesk include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29309: Comdev Contact Form include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29310: Comdev Vote Caster include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29311: Comdev Newsletter include.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29833: Comdev Misc Tools adminfoot.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29844: Comdev Forum adminfoot.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29845: Comdev Form Designer adminfoot.php path[docroot] Variable Remote File Inclusion
- OSVDB ID: 29846: Comdev Web Blogger adminfoot.php path[docroot] Variable Remote File Inclusion
- SA22133: Comdev Newsletter "path[docroot]" Parameter File Inclusion
- SA22134: Comdev eCommerce "path[docroot]" Parameter File Inclusion
- SA22135: Comdev FAQ Support "path[docroot]" Parameter File Inclusion
- SA22147: Comdev Guestbook "path[docroot]" Parameter File Inclusion
- SA22149: Comdev CSV Importer "path[docroot]" Parameter File Inclusion
- SA22151: Comdev Contact Form "path[docroot]" Parameter File Inclusion
- SA22153: Comdev Web Blogger "path[docroot]" Parameter File Inclusion
- SA22154: Comdev Customer Helpdesk "path[docroot]" Parameter File Inclusion
- SA22157: Comdev Vote Caster "path[docroot]" Parameter File Inclusion
- SA22168: Comdev News Publisher "path[docroot]" Parameter File Inclusion
- SA22169: Comdev Photo Gallery "path[docroot]" Parameter File Inclusion
- SA22170: Comdev Links Directory "path[docroot]" Parameter File Inclusion
- SA22433: Comdev Web Blogger "path[docroot]" File Inclusion
- SA22459: Comdev Form Designer "path[docroot]" File Inclusion
- SA22464: Comdev Forum "path[docroot]" File Inclusion
- SA22470: Comdev Misc Tools "path[docroot]" File Inclusion
- VUPEN/ADV-2006-3803: Comdev Vote Caster path[docroot] Parameter Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-3804: Comdev Photo Gallery path[docroot] Parameter PHP File Inclusion Vulnerability
- VUPEN/ADV-2006-3805: Comdev Links Directory path[docroot] Parameter PHP File Inclusion Vulnerability
- VUPEN/ADV-2006-3806: Comdev News Publisher path[docroot] Parameter PHP File Inclusion Vulnerability
- VUPEN/ADV-2006-3807: Comdev Customer Helpdesk path[docroot] Parameter File Inclusion Vulnerability
- VUPEN/ADV-2006-3808: Comdev FAQ Support path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-3809: Comdev Guestbook path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-3810: Comdev eCommerce path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-3811: Comdev Contact Form path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-3812: Comdev CSV Importer path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-3813: Comdev Web Blogger path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-3814: Comdev Newsletter path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-3815: Comdev Events Calendar path[docroot] Parameter File Inclusion Vulnerability
- VUPEN/ADV-2006-4101: Comdev Misc Tools path[docroot] Parameter Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-4102: Comdev Web Blogger path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-4103: Comdev Form Designer path[docroot] Variable Remote File Inclusion Vulnerability
- VUPEN/ADV-2006-4104: Comdev Forum path[docroot] Variable Remote PHP File Inclusion Vulnerability
Platforms Affected:
- Comdev Comdev Contact Form 3.1 and prior
- Comdev Comdev CSV Importer 3.1
- Comdev Comdev Customer Helpdesk 3.1 and prior
- Comdev Comdev eCommerce 3.1 and prior
- Comdev Comdev Events Calendar 3.1
- Comdev Comdev FAQ Support 3.1 and prior
- Comdev Comdev Guestbook 3.1 and prior
- Comdev Comdev Links Directory 3.1 and prior
- Comdev Comdev News Publisher 3.1
- Comdev Comdev Newsletter 3.1
- Comdev Comdev One Admin Pro 4.1
- Comdev Comdev Photo Gallery 3.1 and prior
- Comdev Comdev Vote Caster 3.1 and prior
- Comdev Comdev Web Blogger 3.1 and prior
Reported:
Sep 27, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
