ID

VAR-E-200608-0343


TITLE

Multiple SAPID Products Multiple Remote File Include Vulnerabilities

Trust: 0.3

sources: BID: 19383

DESCRIPTION

Multiple SAPID applications are prone to multiple remote file-include vulnerabilities.
An attacker can exploit these issues to execute arbitrary malicious PHP code in the context of the webserver process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Trust: 0.3

sources: BID: 19383

AFFECTED PRODUCTS

vendor:sapidmodel:shopscope:eqversion:1.2

Trust: 0.3

vendor:sapidmodel:galleryscope:eqversion:1

Trust: 0.3

vendor:sapidmodel:cms rc5scope:eqversion:1.2.3

Trust: 0.3

vendor:sapidmodel:cms rc3scope:eqversion:1.2.3

Trust: 0.3

vendor:sapidmodel:cms rc2scope:eqversion:1.2.3

Trust: 0.3

vendor:sapidmodel:cmsscope:eqversion:1.2.3

Trust: 0.3

vendor:sapidmodel:blog betascope:eqversion:2

Trust: 0.3

sources: BID: 19383

EXPLOIT

Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available as well as an exploit:
Bullet list:
<li><a href="/data/vulnerabilities/exploits/19383-rfi.html">/data/vulnerabilities/exploits/19383-rfi.html</a></li>
<li><a href="/data/vulnerabilities/exploits/19383-rfi.pl">/data/vulnerabilities/exploits/19383-rfi.pl</a></li>

Trust: 0.3

sources: BID: 19383

PRICE

Free

Trust: 0.3

sources: BID: 19383

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 19383

CREDITS

Simo64 and Kacper are credited with the discovery of these vulnerabilities.

Trust: 0.3

sources: BID: 19383

EXTERNAL IDS

db:BIDid:19383

Trust: 0.3

sources: BID: 19383

REFERENCES

url:http://sourceforge.net/project/showfiles.php?group_id=118100

Trust: 0.3

sources: BID: 19383

SOURCES

db:BIDid:19383

LAST UPDATE DATE

2022-07-27T10:02:11.278000+00:00


SOURCES UPDATE DATE

db:BIDid:19383date:2006-08-08T04:06:00

SOURCES RELEASE DATE

db:BIDid:19383date:2006-08-07T00:00:00