发布时间 :2004-12-31 00:00:00
修订时间 :2009-04-03 00:00:00

[原文]Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters.

[CNNVD]PHPHeaven PHPMyChat多个远程漏洞(CNNVD-200412-860)

        PHPMyChat 0.14.5的admin.php3存在多个目录遍历漏洞。拥有管理员特权的远程攻击者可以借助(1) sheet和(2)What参数中的..(点 点)读取任意文件。

- CVSS (基础分值)

CVSS分值: 2.6 [轻微(LOW)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: NONE [对系统可用性无影响]
攻击复杂度: HIGH [漏洞利用存在特定的访问条件]
攻击向量: NETWORK [攻击者不需要获取内网访问权或本地访问权]
身份认证: NONE [漏洞利用无需身份认证]

- CWE (弱点类目)

CWE-22 [对路径名的限制不恰当(路径遍历)]

- CPE (受影响的平台与产品)


- OVAL (用于检测的技术细节)


- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  BID  10556
(UNKNOWN)  BUGTRAQ  20040422 phpMyChat 0.14.5

- 漏洞信息

PHPHeaven PHPMyChat多个远程漏洞
低危 路径遍历
2004-12-31 00:00:00 2009-04-03 00:00:00
        PHPMyChat 0.14.5的admin.php3存在多个目录遍历漏洞。拥有管理员特权的远程攻击者可以借助(1) sheet和(2)What参数中的..(点 点)读取任意文件。

- 公告与补丁

        Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: .

- 漏洞信息 (24217)

phpHeaven phpMyChat 0.14.5 admin.php3 Arbitrary File Access (EDBID:24217)
php webapps
2004-06-15 Verified
N/A [点击下载]
phpHeaven phpMyChat is reported prone to multiple vulnerabilities. The issues result from insufficient sanitization of user-supplied data and design flaws. The following specific issues can affect the application:
phpMyChat is prone to a HTML injection vulnerability. The issue affects the 'input.php3' script. Due to a lack of sufficient sanitization of user-supplied data, this HTML Injection vulnerability may permit an attacker to inject malicious HTML or script code into the affected application. Users who are connected to this session would have the attacker supplied HTML code rendered in their browser in the context of the vulnerable site.
phpMyChat is prone to multiple SQL injection vulnerabilities. Again the issues are due to a failure of the application to properly sanitize user-supplied input. The problem presents itself when SQL syntax is passed through the URI parameters of the 'usersL.php3' script. The offending parameters are used in SQL queries prior to proper sanitization.
An authentication bypass vulnerability is reported to affect the phpMyChat authentication system. It is reported that by saving and modifying the phpMyChat authentication screen an attacker may potentially bypass the authentication system.
Finally phpMyChat is reported to be prone to a file disclosure vulnerability. A user who is authenticated as a site administrator can exploit the issue. The vulnerability presents itself because directory traversal sequences are not correctly sanitized from user-supplied data. It is reported that an attacker may disclose a target file by including a relative path including directory traversal sequences to the target file as a value for a URI parameter passed to the 'admin.php3' script.[USER]&pswd=[YOU HASH PASSWORD]&sheet=[FILE]%00
http://[[YOU HASH PASSWORD]&sheet=/../../../../../../etc/passwd%00
and[FILE]%00&L=russian&user=[USER]&pswd=[YOU HASH PASSWORD]&sheet=1[YOU HASH PASSWORD]&sheet=1		

- 漏洞信息

phpMyChat admin.php3 Arbitrary File Access
Remote / Network Access Input Manipulation
Loss of Confidentiality
Exploit Public

- 漏洞描述

phpMyChat contains a flaw that allows a remote attacker to read files outside of the web path. The issue is due to the admin.php3 script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the sheet and What variables. The flaw can only be exploited by the administrator of the phpMyChat system.

- 时间线

2004-04-22 Unknow
2004-04-22 Unknow

- 解决方案

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

- 相关参考

- 漏洞作者