Re: PHPNuke viewpage.php allows Remote File retrieving

From: Jim Geovedi (negativeat_private)
Date: Tue Mar 25 2003 - 11:28:21 PST

  • Next message: securityat_private: "Security Update: [CSSA-2003-015.0] Linux: apcupsd remote root vulnerability and buffer overflows"

    On Tue, 25 Mar 2003 11:59:26 -0600 DaiTengu wrote:
    > > viewpage.php is a part of PHPNuke.
    > > The Script allows an attacker to view all files on the System.
    > > 
    > > Example:
    > > 
    > > http://server.com/viewpage.php?file=/etc/passwd
    > 
    > umm, what version of phpNuke is vulnerable to this? as far as I'm
    > aware, there has not been any viewpage.php since before 5.0...
    > 
    > I beleive this was reported then as well. 
    > reguardless, this is not true with 6.0
    
    it's repeatable on PHP-Nuke 6.5.
    
    -- 
    	Jim Geovedi <negativeat_private>
    



    This archive was generated by hypermail 2b30 : Tue Mar 25 2003 - 12:42:28 PST