Local File Include Vulnerability (code execution) [FIXED]

Tell us what's wrong.

Local File Include Vulnerability (code execution) [FIXED]

Postby munozferna on Tue Jul 31, 2007 12:20 am

I got across this issue a couple days ago while inspecting language translations, Claroline doesn't validate the user supplied parameter for language, so by ussing something like ./../../../../../../../../../../../etc/passwd%00 it will allow to include files, this can be abussed to read system configuration files, and execute code if users are allowed to upload txt or image files with php code, or injecting PHP code in httpd logs and including them. This bug seems to affect several instalations regardless magic_quotes_gpc settings since claroline uses an internal funcion for disabling it.

url removed I removed the url for more confidentiality (Mathieu Laurent)

Although is kinda obvious, the vulnerable code is on this file:

http://cvs.claroline.net/cgi-bin/viewcv ... iew=markup
- Fernando Muñoz
munozferna
 
Posts: 13
Joined: Sun Feb 04, 2007 2:44 am

Postby marlon on Tue Jul 31, 2007 1:58 am

it´s a problem....
marlon
 
Posts: 20
Joined: Tue Mar 08, 2005 7:38 pm

Postby zefredz on Tue Jul 31, 2007 7:14 am

Hello Fernando,

Thanks a lot for reporting this important issue.

I have reported it on our bug tracker http://jupiter.cerdecam.be/bug/view.php?id=943 and we will correct it in the next few hours and provide a patch.

Regards,
Frederic Minne (ZeFredz) - Claroline Team - Claroline.net
Image
User avatar
zefredz
Contributeurs Actif Forum
 
Posts: 986
Joined: Thu Sep 02, 2004 1:41 pm
Location: Belgium, LLN

Postby zefredz on Tue Jul 31, 2007 8:43 am

The bug is fixed, here is the diff : http://cvs.claroline.net/cgi-bin/viewcv ... 2=1.28.2.2

We will provide a patch or release a new version of Claroline as soon as possible.

Regards,
Frederic Minne (ZeFredz) - Claroline Team - Claroline.net
Image
User avatar
zefredz
Contributeurs Actif Forum
 
Posts: 986
Joined: Thu Sep 02, 2004 1:41 pm
Location: Belgium, LLN

Postby munozferna on Wed Aug 01, 2007 4:09 am

This may sound kind of selfish, but there is a section on http://cvs.claroline.net/cgi-bin/viewcv ... iew=markup that needs to get updated too :P

- Fernando Muñoz
munozferna
 
Posts: 13
Joined: Sun Feb 04, 2007 2:44 am

Postby zefredz on Wed Aug 01, 2007 7:16 am

Hello Fernando,

Yes, the credits file is completely outdated. Even the core teams at Cerdecam and IPM are no longer correct.

We will update the file as soon as possible and add your name to the security section.

Regards,
Frederic Minne (ZeFredz) - Claroline Team - Claroline.net
Image
User avatar
zefredz
Contributeurs Actif Forum
 
Posts: 986
Joined: Thu Sep 02, 2004 1:41 pm
Location: Belgium, LLN


Return to Bugs Claroline 1.8.11

Who is online

Users browsing this forum: No registered users and 0 guests