OSVDB ID: 86077

Title: AstroCMS /include/get_js.php4 fname Parameter Arbitrary File Access

Info

Disclosure

Sep 12, 2011

Discovery

Unknown

Dates

Exploit

Sep 12, 2011

Solution

Unknown

Description

AstroCMS contains a flaw that is triggered when input passed via the 'fname' parameter is not properly sanitized before being used in the /include/get_js.php4 script. By specifying an arbitrary file using an absolute path, the server will return the contents of the file, limited to the privileges of the web server running process.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality
Solution: Solution Unknown
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure
OSVDB: Web Related

Solution

OSVDB is not aware of a solution for this vulnerability.

Products

Astron Systems LLC

AstroCMS

Unspecified

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/86077