Likes Likes:  0
Resultaten 1 tot 8 van de 8
Geen
  1. #1
    Zero_X www.lobnan.de Team
    PHPNuke viewpage.php allows Remote File retrieving
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    PHPNuke viewpage.php allows Remote File retrieving



    viewpage.php is a part of PHPNuke.
    The Script allows an attacker to view all files on the System.

    Example:

    http://server.com/viewpage.php?file=/etc/passwd


    Zero X member of www.Lobnan.de

  2. #2
    DaiTengu
    PHPNuke viewpage.php allows Remote File retrieving
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHPNuke viewpage.php allows Remote File retrieving

    Zero_X www.lobnan.de Team wrote:
    >
    > viewpage.php is a part of PHPNuke.
    > The Script allows an attacker to view all files on the System.
    >
    > Example:
    >
    > http://server.com/viewpage.php?file=/etc/passwd
    >
    >
    >

    umm, what version of phpNuke is vulnerable to this? as far as I'm aware,
    there has not been any viewpage.php since before 5.0...

    I beleive this was reported then as well.

    reguardless, this is not true with 6.0


    --
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Mike "DaiTengu" Miller
    UA Site Coordinator: http://www.unitedadmins.com
    Webmaster: http://war-ensemble.com
    Sysop: telnet://bbs.war-ensemble.com
    StatsMe Team: http://www.unitedadmins.com/StatsMe.php
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-


  3. #3
    Jim Geovedi
    PHPNuke viewpage.php allows Remote File retrieving
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHPNuke viewpage.php allows Remote File retrieving

    On Tue, 25 Mar 2003 11:59:26 -0600 DaiTengu wrote:
    > > viewpage.php is a part of PHPNuke.
    > > The Script allows an attacker to view all files on the System.
    > >
    > > Example:
    > >
    > > http://server.com/viewpage.php?file=/etc/passwd

    >
    > umm, what version of phpNuke is vulnerable to this? as far as I'm
    > aware, there has not been any viewpage.php since before 5.0...
    >
    > I beleive this was reported then as well.
    > reguardless, this is not true with 6.0


    it's repeatable on PHP-Nuke 6.5.

    --
    Jim Geovedi <negative@magnesium.net>

  4. #4
    PHPNuke viewpage.php allows Remote File retrieving
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHPNuke viewpage.php allows Remote File retrieving

    In-Reply-To: <20030326022821.48e4e54f.negative@magnesium.net>

    >From: Jim Geovedi <negative@magnesium.net>
    >To: bugtraq@securityfocus.com
    >Subject: Re: PHPNuke viewpage.php allows Remote File retrieving
    >Message-Id: <20030326022821.48e4e54f.negative@magnesium.net>
    >In-Reply-To: <3E8098FE.3070808@war-ensemble.com>
    >References: <20030325163207.13063.qmail@www.securityfocus.com>
    > <3E8098FE.3070808@war-ensemble.com>
    >Organization: Will Work For Bandwidth, Inc.
    >X-Mailer: Superunknown.
    >Mime-Version: 1.0
    >Content-Type: text/plain; charset=US-ASCII
    >Content-Transfer-Encoding: 7bit
    >
    >On Tue, 25 Mar 2003 11:59:26 -0600 DaiTengu wrote:
    >> > viewpage.php is a part of PHPNuke.
    >> > The Script allows an attacker to view all files on the System.
    >> >
    >> > Example:
    >> >
    >> > http://server.com/viewpage.php?file=/etc/passwd

    >>
    >> umm, what version of phpNuke is vulnerable to this? as far as I'm
    >> aware, there has not been any viewpage.php since before 5.0...
    >>
    >> I beleive this was reported then as well.
    >> reguardless, this is not true with 6.0

    >
    >it's repeatable on PHP-Nuke 6.5.
    >
    >--
    > Jim Geovedi <negative@magnesium.net>
    >

    I have the vanilla 6.5 and there is no viewpage.php file in the package
    that I can find. Are you sure that this isn't in an addon? Or possibly
    left over from a previous version that was never cleared out when phpnuke
    was updated?

  5. #5
    Christopher Warner
    PHPNuke viewpage.php allows Remote File retrieving
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHPNuke viewpage.php allows Remote File retrieving

    --=-Z6yoZrxLZ0IqN0N35CmZ
    Content-Type: text/plain
    Content-Transfer-Encoding: quoted-printable

    If you could follow up on this and give more details (versions affected)
    etc etc; as it stands I'm gonna confirm that viewpage.php hasn't existed
    for quite some time and that this is a pretty pointless advisory.

    Thanks,
    Christopher Warner

    On Tue, 2003-03-25 at 14:28, Jim Geovedi wrote:
    > On Tue, 25 Mar 2003 11:59:26 -0600 DaiTengu wrote:
    > > > viewpage.php is a part of PHPNuke.
    > > > The Script allows an attacker to view all files on the System.
    > > >=20
    > > > Example:
    > > >=20
    > > > http://server.com/viewpage.php?file=3D/etc/passwd

    > >=20
    > > umm, what version of phpNuke is vulnerable to this? as far as I'm
    > > aware, there has not been any viewpage.php since before 5.0...
    > >=20
    > > I beleive this was reported then as well.=20
    > > reguardless, this is not true with 6.0

    >=20
    > it's repeatable on PHP-Nuke 6.5.


    --=-Z6yoZrxLZ0IqN0N35CmZ
    Content-Type: application/pgp-signature; name=signature.asc
    Content-Description: This is a digitally signed message part

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.7 (GNU/Linux)

    iD8DBQA+gQxgiEj62/Q89msRApgQAKDbqNi6w0Ji3NFfebJFoq35vhW7LgCgpIS4
    h163q19H+4Kc3+EiioN6Azc=
    =xk5j
    -----END PGP SIGNATURE-----

    --=-Z6yoZrxLZ0IqN0N35CmZ--


  6. #6
    Tonu Samuel
    PHPNuke viewpage.php allows Remote File retrieving
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHPNuke viewpage.php allows Remote File retrieving

    On Tue, 2003-03-25 at 21:28, Jim Geovedi wrote:
    > On Tue, 25 Mar 2003 11:59:26 -0600 DaiTengu wrote:
    > > > viewpage.php is a part of PHPNuke.
    > > > The Script allows an attacker to view all files on the System.
    > > >=20
    > > > Example:
    > > >=20
    > > > http://server.com/viewpage.php?file=3D/etc/passwd


    Not repeatable with 6.0

    T=F5nu


  7. #7
    Kevin
    PHPNuke viewpage.php allows Remote File retrieving
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHPNuke viewpage.php allows Remote File retrieving

    I have just checked 5 different 6.5 installs some of which have been
    upgraded from previous 6.5 beta's and this file most definattly does not
    exist under 6.5

    admin@gaylenandmargie.com wrote:

    >In-Reply-To: <20030326022821.48e4e54f.negative@magnesium.net>
    >
    >
    >
    >>From: Jim Geovedi <negative@magnesium.net>
    >>To: bugtraq@securityfocus.com
    >>Subject: Re: PHPNuke viewpage.php allows Remote File retrieving
    >>Message-Id: <20030326022821.48e4e54f.negative@magnesium.net>
    >>In-Reply-To: <3E8098FE.3070808@war-ensemble.com>
    >>References: <20030325163207.13063.qmail@www.securityfocus.com>
    >> <3E8098FE.3070808@war-ensemble.com>
    >>Organization: Will Work For Bandwidth, Inc.
    >>X-Mailer: Superunknown.
    >>Mime-Version: 1.0
    >>Content-Type: text/plain; charset=US-ASCII
    >>Content-Transfer-Encoding: 7bit
    >>
    >>On Tue, 25 Mar 2003 11:59:26 -0600 DaiTengu wrote:
    >>
    >>
    >>>>viewpage.php is a part of PHPNuke.
    >>>>The Script allows an attacker to view all files on the System.
    >>>>
    >>>>Example:
    >>>>
    >>>>http://server.com/viewpage.php?file=/etc/passwd
    >>>>
    >>>>
    >>>umm, what version of phpNuke is vulnerable to this? as far as I'm
    >>>aware, there has not been any viewpage.php since before 5.0...
    >>>
    >>>I beleive this was reported then as well.
    >>>reguardless, this is not true with 6.0
    >>>
    >>>

    >>it's repeatable on PHP-Nuke 6.5.
    >>
    >>--
    >> Jim Geovedi <negative@magnesium.net>
    >>
    >>
    >>

    > I have the vanilla 6.5 and there is no viewpage.php file in the package
    >that I can find. Are you sure that this isn't in an addon? Or possibly
    >left over from a previous version that was never cleared out when phpnuke
    >was updated?
    >
    >
    >




  8. #8
    PHPNuke viewpage.php allows Remote File retrieving
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHPNuke viewpage.php allows Remote File retrieving

    In-Reply-To: <1048644704.1429.19.camel@localhost.localdomain>

    >From: Christopher Warner <zanee@kernelcode.com>
    >
    >If you could follow up on this and give more details (versions affected)
    >etc etc; as it stands I'm gonna confirm that viewpage.php hasn't existed
    >for quite some time and that this is a pretty pointless advisory.
    >
    >Thanks,
    >Christopher Warner
    >


    This is NOT a phpnuke file and never has been. It can be traced to
    NukeStyles (http://www.nukestyles.com/). See this thread/discussion:
    http://nukecops.com/postx1337-0-0.html

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics