[VIM] CoolMenus Event Remote File Inclusion exploit (fwd)

Steven M. Christey coley at linus.mitre.org
Mon May 1 17:23:53 EDT 2006

botan keeps showing up with these major errors or inconsistencies.  Maybe
he's doing live site testing and misinterpreting results?

---------- Forwarded message ----------
Date: Mon, 1 May 2006 17:20:09 -0400 (EDT)
From: Steven M. Christey <coley at mitre.org>
To: bugtraq at securityfocus.com
Subject: Re: CoolMenus Event Remote File Inclusion exploit

botan at linuxmail.org said:

>#Website : http://coolmenus.dhtmlcentral.com/projects/coolmenus
> [Closed]

The new URL appears to be here:


>#ColMenus Event Remote File Include Vulnerability#

The CoolMenus code does not appear to be written in PHP.

Downloading the source code from the above URL, we see that there are
a couple ASP files, and mostly .js and .html files.

So, this code is NOT present in CoolMenus:

> require("event_inc.php");
>$start = filectime($news);
>$jetzt = time();
>$update = "$start"+"$timespan";
>if($jetzt >= $update)

(I grepped through version 4 beta 1.06 just to be sure).

However, it looks almost exactly like the code from this disclosure
for Artmedic Event:

  [Kurdish Security #2] Artmedic Event Remote File Include Vulnerability

with a small difference in variables and file names.

With a download of artmedic event 2.0 from here:


we can see that the above code came from artmedic_event.php.


- CoolMenus is being claimed to be vulnerable to PHP remote file
  inclusion, when it isn't written in PHP;

- source code is being quoted which does not exist in CoolMenus

- the quoted source code appears to be derived from artmedic event,
  although there are some changes that are not explained

In short, it is very difficult to figure out what vulnerability is
being reported, and for what product.

- Steve

More information about the VIM mailing list