功能模组
· 首页
· 信息反馈
· 归档资讯
· 投递资讯
· 档案下载
· 民意调查
· 热门排行
· 百科全书
· 私人讯息
· 站内搜索
· 网站链接
· 资讯专题
美图欣赏
闪动新闻

ENews 晚报相关资讯
[ ENews 晚报相关资讯 ]

· 上海政协委员建议:给全国每人发1000元
· 张艺谋:奥运会开幕式表演夸张且独特
· 北京奥运是商家一辈子一次的机遇
· 英式性感的脱衣女郎
· 老妇少夫 永葆青春的“秘药”
· 少了份真诚 多了几分浮躁
· 美六家电影公司起诉迅雷索赔百万美元
· “熊猫烧香”设计者承认已获利上千万
· 全球痢疾肆虐 中国股市受染 狂泻
网站信息
你的 IP: 38.103.63.61

欢迎, 来访客人
登入名称
密码
安全确认码
安全确认码
在此输入安全确认码


· 注册
· 遗失密码
服务器 日期/时间
2008-08-28 12:18:52 CST (GMT +8)
我的最爱
Powered by RavenNuke(tm)

PHPNuke utf-8 中文测试网
推荐网站
CSE HTML Validator Helped Clean up This Page!

PC Sympathy - Your Source for PC News and Technical Support

Totally Nuked Mods

Mantis Bugtracker

nukeresources.com

nukescripts.net

Montego Scripts - Home of HTML Newsletter

ROG_BBtoNuke_Mods_Mal3:2-3

Jaded-Designs...Where Imagination And Reality Meet

Maty Scripts - Home of MS-Analysis

Dezina Themes

A Top Site Where Quality Does Matter

CPGNuke - it''s Fast, Secure, and Free

Comunidade PHP-Nuke Brasil - CNB

Codezwiz Your #1 Help Resource





pcnuke.com

FLASH-FOR-NUKE

Nuclear Nuke PHP-Nuke Web Design

Am-nuke.net Webmasters Resource

NUKE4GAMERS

DaDaNuke.org

SDDesign.biz - Designing reliable,affordable, supported, FREE and unique php nuke themes

亲密伙伴

IT业界资讯站

米客网

NukeSentinel(tm)
You have been warned!
We have caught 133 shameful hackers.

NukeSentinel(tm) 2.5.16
PHP-Nuke Addressbook Module *module_name* Local File Inclusion
RavenNuke(tm)VERIFY ADVISORY: http://secunia.com/advisories/24697/

CRITICAL: Moderately critical

IMPACT: Exposure of system information, Exposure of sensitive information

WHERE: >From remote

SOFTWARE: Addressbook 1.x (module for PHP-Nuke) - http://secunia.com/product/13832/

DESCRIPTION: bd0rk has discovered a vulnerability in the Addressbook module for PHP-Nuke, which can be exploited by malicious people to disclose sensitive information.

Input passed to the "module_name" parameter in modules/Addressbook/addressbook.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources. Successful exploitation requires that "register_globals" is enabled, "magic_quotes_gpc" is disabled, and that the system is running PHP5. The vulnerability is confirmed in version 1.2. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly verified.

PROVIDED AND/OR DISCOVERED BY: bd0rk

ORIGINAL ADVISORY: http://milw0rm.com/exploits/3582
发表于 2007-04-08 @ 02:30:47 由 mcoole
PHP-Nuke Addressbook Module *module_name* Local File Inclusion | 登入/产生新的帐号 | 0 意见
著作权属于原作者,本站对内容不负任何责任
 
相关的链结
· 更多相关的 RavenNuke(tm)
· 新闻来源为 mcoole


最受欢迎的报导,关于 RavenNuke(tm):
PHP-Nuke Addressbook Module *module_name* Local File Inclusion

文章评分
平均分数: 0
投票: 0

请花一秒钟给这篇文章一个分数:

完美
非常好
好
一般
差

选项

 友善列印格式 友善列印格式