Description
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outside the web root. The vulnerability is further exacerbated by null byte injection (%00) to bypass file extension checks.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
2011.3
Credits
blkhtc0rp
References
raw.githubusercontent.com/...er/http/clansphere_traversal.rb
www.exploit-db.com/exploits/22181
raw.githubusercontent.com/...er/http/clansphere_traversal.rb
www.exploit-db.com/exploits/22181
sourceforge.net/projects/clansphere/
www.vulncheck.com/...nsphere-local-file-inclusion-via-cookie