Re: PTNews v1.7.7 - Access to administrator functions without authentification

From: Rui Pimenta (rui.pimentaat_private)
Date: Tue Apr 29 2003 - 05:57:05 PDT

  • Next message: J.'LoneWolf' Mattsson: "RE: Windows Server 2003 Security Guide available"

    Update: 
    
    Create News: URL Exploitable
    Replace Nnews: URL Exploitable
    Edit News: URL Exploitable
    
    It's just a matter of learning the indexing structures.
    
    
    ----- Original Message ----- 
    From: "scrap" <webmasterat_private>
    To: <bugtraqat_private>
    Sent: Monday, April 21, 2003 9:49 PM
    Subject: PTNews v1.7.7 - Access to administrator functions without authentification
    
    
    [snip]
    
    Function / URL :
    Create a news / Not an URL : only posted datas. Not impossible to exploit :)
    Replace a news / Not an URL : only posted datas. Not impossible to exploit :)
    Delete all news / http://www.victim.com/ptnews/ index.php?delete=all
    Edit a news / Too difficult to exploit
    
    http://www.openbg.net/ptsite/
    
    
    



    This archive was generated by hypermail 2b30 : Tue Apr 29 2003 - 10:50:35 PDT