NASLDB: AppServ appserv/main.php appserv_root Parameter Remote File Inclusion
General
ID: 20383
Name: AppServ appserv/main.php appserv_root Parameter Remote File Inclusion
Summary: Checks for appserv_root parameter remote file include vulnerability in AppServ
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS Temporal Vector: CVSS2#E:H/RL:W/RC:ND
Port: 80
Family: CGI abuses
Type: Remote
Description
The remote host appears to be running AppServ, a compilation of
Apache, PHP, MySQL, and phpMyAdmin for Windows and Linux.
The version of AppServ installed on the remote host fails to sanitize
user supplied input to the ‘appserv_root’ parameter of the
‘appserv/main.php’ script before using it in a PHP ‘include’ function.
An unauthenticated attacker can exploit this flaw to run arbitrary
code, possibly taken from third-party hosts, subject to the privileges
of the web server user id. Note that AppServ under Windows runs with
SYSTEM privileges, which means an attacker can gain complete control
of the affected host.
Exploiting
Exploit Available: True
Exploitability Ease: No exploit is required
Sources
CVE: CVE-2006-0125
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2006/01/05
Patch Release: –
Plugin Release: 2006/01/10
Plugin
Version: 1.15
Filename: appserv_appserv_root_includes.nasl
Filesize: 2871 bytes
MD5 Hash: 3b743206543be4957037b60bf59f1cf7
Identification: –
Require Keys: www/PHP
Dependencies: "http_version.nasl"
Copyright: This script is Copyright© 2006-2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













