-
-
[转帖][推荐]Joomla Component Jgrid 1.0 Local File Inclusion Vulnerability
-
发表于: 2010-8-18 06:13 2372
-
[转帖][推荐]Joomla Component Jgrid 1.0 Local File Inclusion Vulnerability
2010-8-18 06:13
2372
Jgrid 1.0 Joomla Component Local File Inclusion Vulnerability
Name Jgrid
Vendor f9eK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3c8S2N6r3q4Y4M7X3W2V1M7#2)9J5k6h3y4D9N6h3u0K6j5i4u0W2N6i4y4Q4x3X3g2G2M7X3N6Q4x3U0k6F1j5Y4y4H3i4K6y4n7i4K6t1$3L8X3u0K6M7q4)9K6b7R3`.`.
Versions Affected 1.0
X. INDEX
I. ABOUT THE APPLICATION
II. DESCRIPTION
III. ANALYSIS
IV. SAMPLE CODE
V. FIX
I. ABOUT THE APPLICATION
________________________
DATA GRID Component built on the popular EXTJS Framework.
II. DESCRIPTION
_______________
A parameter is not properly sanitised before being used
by the require_once function.
III. ANALYSIS
_____________
Summary:
A) Local File Inclusion
A) Local File Inclusion
_______________________
The controller parameter in jgrid.php is not sanitised
before being used by the PHP function's require_once().
This allows a guest to include local files. The following
is the affected code:
if($controller = JRequest::getVar('controller')) {
require_once (JPATH_COMPONENT.DS.'controllers'.DS.$controller.'.php');
}
IV. SAMPLE CODE
_______________
A) Local File Inclusion
d1dK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4y4A6N6r3g2Q4x3V1k6H3j5i4c8Z5i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6G2M7s2c8A6L8$3&6Q4x3@1c8U0L8$3#2Q4y4h3k6B7k6%4u0A6k6q4)9J5y4X3y4G2L8Y4c8J5L8$3I4D9k6i4u0Q4x3@1c8Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6W2N6r3y4Q4x3V1k6H3j5i4y4K6N6$3c8Q4x3U0f1H3x3q4)9J5y4X3&6T1M7%4m8Q4x3@1u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7
V. FIX
______
No fix.
Name Jgrid
Vendor f9eK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3c8S2N6r3q4Y4M7X3W2V1M7#2)9J5k6h3y4D9N6h3u0K6j5i4u0W2N6i4y4Q4x3X3g2G2M7X3N6Q4x3U0k6F1j5Y4y4H3i4K6y4n7i4K6t1$3L8X3u0K6M7q4)9K6b7R3`.`.
Versions Affected 1.0
X. INDEX
I. ABOUT THE APPLICATION
II. DESCRIPTION
III. ANALYSIS
IV. SAMPLE CODE
V. FIX
I. ABOUT THE APPLICATION
________________________
DATA GRID Component built on the popular EXTJS Framework.
II. DESCRIPTION
_______________
A parameter is not properly sanitised before being used
by the require_once function.
III. ANALYSIS
_____________
Summary:
A) Local File Inclusion
A) Local File Inclusion
_______________________
The controller parameter in jgrid.php is not sanitised
before being used by the PHP function's require_once().
This allows a guest to include local files. The following
is the affected code:
if($controller = JRequest::getVar('controller')) {
require_once (JPATH_COMPONENT.DS.'controllers'.DS.$controller.'.php');
}
IV. SAMPLE CODE
_______________
A) Local File Inclusion
d1dK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4y4A6N6r3g2Q4x3V1k6H3j5i4c8Z5i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6G2M7s2c8A6L8$3&6Q4x3@1c8U0L8$3#2Q4y4h3k6B7k6%4u0A6k6q4)9J5y4X3y4G2L8Y4c8J5L8$3I4D9k6i4u0Q4x3@1c8Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6Q4x3X3g2Q4x3X3g2Q4x3V1k6W2N6r3y4Q4x3V1k6H3j5i4y4K6N6$3c8Q4x3U0f1H3x3q4)9J5y4X3&6T1M7%4m8Q4x3@1u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7
V. FIX
______
No fix.
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课
赞赏
他的文章
赞赏
雪币:
留言: