Destiney Links is an Open Source project written in PHP for use with the
MySQL Server entity. Links provides a pre-built, dynamically generated,
Link site. Links counts referrers in and out for listed sites. Links
provides site categorization up to 5 levels dee
Effected Files:
index.php
Exploits:
Almost all files called directly from the /include/ folder and
/themes/original/ displays full path disclosure errors.
Input data in the Search and Add a Site forms arent filtered and sanatized.
Attacks such as XSS' can occure because of that.
URL injection of index.php can lead to full path disclosure errors.
URL Example:
http://links.destiney.com/index.php?show=pop'
Warning: include(include/pop'.php) [function.include]: failed to open
stream: No such file or directory in
/home/destiney/domains/examplesite.com/public_html/index.php on line 98
Warning: include() [function.include]: Failed opening 'include/pop'.php'
for inclusion (include_path='.:/usr/share/php5:/usr/share/php') in
/home/destiney/domains/examplesite.com/public_html/index.php on line 98
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.