If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive : exploit()securityreason()com
Details : SecurityReason Advisory
Topic : Multiple vulnerabilities in PostNuke 0.760-RC4b=>x SecurityAlert : 22 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : Yes Exploit Given : Yes Credit : Maksymilian Arciemowicz Date : 10.09.2005
Affected Software :
PostNuke 0.760-RC4b=>x
Advisory Text :
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
[Multiple vulnerabilities in PostNuke 0.760-RC4b=>x cXIb8O3.15]
Author: Maksymilian Arciemowicz ( cXIb8O3 )
Date: 22.8.2005
from SECURITYREASON.COM
- --- 0.Description ---
PostNuke: The Phoenix Release (0.750)
PostNuke is an open source, open developement content management system
(CMS). PostNuke started as a fork from PHPNuke (http://www.phpnuke.org) and
provides many enhancements and improvements over the PHP-Nuke system.
PostNuke
is still undergoing development but a large number of core functions are
now
stabilising and a complete API for third-party developers is now in place.
If you would like to help develop this software, please visit our homepage
at http://noc.postnuke.com/
You can also visit us on our IRC Server irc.postnuke.com channel
#postnuke-support
#postnuke-chat
#postnuke
Or at the Community Forums located at:
http://forums.postnuke.com/
- --- 1. Sql injection in Download ---
This sql injection is non critical because exploit works only with admin
rights (mysql).
The problem is in "modules/Downloads/dl-viewdownload.php".
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.