vendor:
Google Urchin
by:
Kristian Erik Hermansen
7.5
CVSS
HIGH
Local File Include (LFI)
22
CWE
Product Name: Google Urchin
Affected Version From: 5.7.03
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
Unknown
Local File Include (LFI) vulnerability in Google Urchin
Google Urchin is vulnerable to a Local File Include (LFI) vulnerability that allows arbitrary reading of files. The vulnerability is caused by improper filtering of included files, which are stored under $INSTALL_PATH. By modifying the 'gfid' parameter in a GET request, an attacker can read any file on the host.
Mitigation:
Filter user input to prevent directory traversal attacks. Update to a patched version of Google Urchin.