|
|
 |
PHP-Nuke Addressbook Module *module_name* Local File Inclusion |
 |
VERIFY ADVISORY: http://secunia.com/advisories/24697/
CRITICAL: Moderately critical
IMPACT: Exposure of system information, Exposure of sensitive information
WHERE: >From remote
SOFTWARE: Addressbook 1.x (module for PHP-Nuke) - http://secunia.com/product/13832/
DESCRIPTION: bd0rk has discovered a vulnerability in the Addressbook module for PHP-Nuke, which can be exploited by malicious people to disclose sensitive information.
Input passed to the "module_name" parameter in modules/Addressbook/addressbook.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources. Successful exploitation requires that "register_globals" is enabled, "magic_quotes_gpc" is disabled, and that the system is running PHP5. The vulnerability is confirmed in version 1.2. Other versions may also be affected.
SOLUTION: Edit the source code to ensure that input is properly verified.
PROVIDED AND/OR DISCOVERED BY: bd0rk
ORIGINAL ADVISORY: http://milw0rm.com/exploits/3582
|
| 发表于 2007-04-08 @ 02:30:47 由 mcoole |
|
|
| PHP-Nuke Addressbook Module *module_name* Local File Inclusion | 登入/产生新的帐号 | 0 意见 | | | 著作权属于原作者,本站对内容不负任何责任 |
|
| |
|
|