83 lines
No EOL
1.8 KiB
Text
83 lines
No EOL
1.8 KiB
Text
[+] Credits: hyp3rlinx
|
|
|
|
[+] Website: hyp3rlinx.altervista.org
|
|
|
|
[+] Source:
|
|
http://hyp3rlinx.altervista.org/advisories/ZEN-PHOTO-1.4.10-LFI.txt
|
|
|
|
|
|
Vendor:
|
|
====================
|
|
www.zenphoto.org
|
|
|
|
|
|
Product:
|
|
===================
|
|
Zenphoto 1.4.10
|
|
|
|
|
|
Vulnerability Type:
|
|
========================
|
|
Local File Inclusion
|
|
|
|
|
|
CVE Reference:
|
|
==============
|
|
N/A
|
|
|
|
|
|
Vulnerability Details:
|
|
======================
|
|
Zen Photos pluginDoc.php PHP file is vulnerable to local file inclusion
|
|
that allows attackers
|
|
to read arbitrary server files outside of the current web directory by
|
|
injecting "../" directory traversal
|
|
characters, which can lead to sensitive information disclosure, code
|
|
execution or DOS on the victims web server.
|
|
|
|
|
|
Local File Inclusion Codes:
|
|
==========================
|
|
http://localhost/zenphoto-zenphoto-1.4.10/zp-core/pluginDoc.php?thirdparty=1&extension=../../../xampp/phpinfo
|
|
|
|
|
|
|
|
Disclosure Timeline:
|
|
=====================
|
|
Vendor Notification: November 10, 2015
|
|
December 1, 2015 : Public Disclosure
|
|
|
|
|
|
Exploitation Technique:
|
|
=======================
|
|
Local
|
|
|
|
|
|
Severity Level:
|
|
================
|
|
High
|
|
|
|
|
|
Description:
|
|
=====================================================
|
|
Request Method(s): [+] GET
|
|
|
|
|
|
Vulnerable Product: [+] Zenphoto 1.4.10
|
|
|
|
|
|
Vulnerable Parameter(s): [+] extension
|
|
|
|
|
|
|
|
[+] Disclaimer
|
|
Permission is hereby granted for the redistribution of this advisory,
|
|
provided that it is not altered except by reformatting it, and that due
|
|
credit is given. Permission is explicitly given for insertion in
|
|
vulnerability databases and similar, provided that due credit is given to
|
|
the author.
|
|
The author is not responsible for any misuse of the information contained
|
|
herein and prohibits any malicious use of all security related information
|
|
or exploits by the author or elsewhere.
|
|
|
|
by hyp3rlinx |