PHP-Nuke 5.5 and 6.0: Path Disclosure

From: Rynho Zeros Web (hackargentinoat_private)
Date: Sat Mar 15 2003 - 15:59:39 PST

  • Next message: Michael Walton: "[Sorcerer-spells] SAMBA-SORCERER2003-03-17"

    +  Product -> PHP-Nuke
    +  Version -> 5.5, 6.0 (other versions not tested jet)
    +  Website -> http://www.phpnuke.org
    + Problems -> Path Disclosure
    
    + Explanation:
    The fault happens in the file print.php, which this including in the modulos
    'News' and 'AvantGo', in the same one is checked that the variable $sid
    exists, but its content is not controlled, since if he is equal to NULL or not it
    corresponds with I articulate in the data base, generates an error.
    
    + Exploit: This vulnerability may be exploited by accessing one of the
    following vulnerable scripts:
    
    http://www.target.x/modules.php?name=AvantGo&file=print&sid=
    http://www.target.x/modules.php?name=News&file=print&sid=
    http://www.target.x/modules.php?name=AvantGo&file=print&sid=[Any_Text]
    http://www.target.x/modules.php?name=News&file=print&sid=[Any_Text]
    
    [..]
    Another one bug also has been found in "Forums" (Splatt Forums
    3.2)
    module:
    
    http://www.target.x/modules.php?op=modload&name=Forums&file=attachment&AtchOp=show
    [..]
    
    + Path AvantGo & News only:
    
    http://www.rynhozeros.com.ar/files/site/own/fixes/PHPNuke6.0_5.5_etc.zip
    
    -- 
    XyBØrG
    WebMaster de:
    www.RZWEB.com.ar
    Powered By Dattatec.Com
    
    +++ GMX - Mail, Messaging & more  http://www.gmx.net +++
    Bitte lächeln! Fotogalerie online mit GMX ohne eigene Homepage!
    



    This archive was generated by hypermail 2b30 : Mon Mar 17 2003 - 13:37:42 PST