Go to:
Gentoo Home
Documentation
Forums
Lists
Bugs
Planet
Store
Wiki
Get Gentoo!
Gentoo's Bugzilla – Attachment 170108 Details for
Bug 244741
net-p2p/ktorrent <2.2.8 web interface plugin vulnerable to PHP injection (CVE-2008-{5905,5906})
Home
|
New
–
[Ex]
|
Browse
|
Search
|
Privacy Policy
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
ktorrent-3.1.3-php-injection.patch
ktorrent-3.1.3-php-injection.patch (text/plain), 1.21 KB, created by
Robert Buchholz (RETIRED)
on 2008-10-28 14:59:47 UTC
(
hide
)
Description:
ktorrent-3.1.3-php-injection.patch
Filename:
MIME Type:
Creator:
Robert Buchholz (RETIRED)
Created:
2008-10-28 14:59:47 UTC
Size:
1.21 KB
patch
obsolete
>--- ktorrent-3.1.3/plugins/webinterface/phphandler.cpp 2008-10-06 18:43:01.000000000 +0200 >+++ ktorrent-3.1.4/plugins/webinterface/phphandler.cpp 2008-10-19 12:23:34.000000000 +0200 >@@ -88,7 +88,9 @@ > QMap<QString,QString>::const_iterator it; > for ( it = args.begin(); it != args.end(); ++it ) > { >- out << QString("$_REQUEST['%1']=\"%2\";\n").arg(it.key()).arg(it.value()); >+ // Check for string delimiters, don't want PHP injection attacks >+ if (!containsDelimiters(it.key()) && !containsDelimiters(it.value())) >+ out << QString("$_REQUEST['%1']=\"%2\";\n").arg(it.key()).arg(it.value()); > } > > out << php_s.mid(firstphptag + 6) << flush; >@@ -111,6 +113,10 @@ > } > } > >+ bool PhpHandler::containsDelimiters(const QString & str) >+ { >+ return str.contains("\"") || str.contains("'"); >+ } > } > > #include "phphandler.moc" >--- ktorrent-3.1.3/plugins/webinterface/phphandler.h 2008-10-06 18:43:01.000000000 +0200 >+++ ktorrent-3.1.4/plugins/webinterface/phphandler.h 2008-10-19 12:23:34.000000000 +0200 >@@ -44,6 +44,9 @@ > void onFinished(int exitCode,QProcess::ExitStatus exitStatus); > void onReadyReadStdout(); > >+ private: >+ bool containsDelimiters(const QString & str); >+ > signals: > void finished(); >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 244741
:
170106
| 170108 |
170109
|
170111