[Full-disclosure] SimplePHPBlog Arbitrary File Deletion and Sample Exploit

'ken'_at_FTU
Date: 08/29/05

  • Next message: yahoo123456_at_hushmail.com: "[Full-disclosure] The Wireless Networking Excuse"
    Date: Mon, 29 Aug 2005 13:28:00 -0400
    To: full-disclosure@lists.grok.org.uk
    
    

    SimplePHPBlog has a vulnerability in its comment_delete_cgi.php.

    The PHP script allows for the arbitrary deletion of files.

    Please see following link for a perl script to demonstrate the exploit:
    http://www.ftusecurity.com/pub/sphpblog_vulns
    (Please add .pl extension as my ISP server preprocesses the file if it
    is .pl or txt.)

    This vulnerability, in combination with the fact that the installation
    scripts are left on the server after installation, allows an arbitrary
    user to reset the admin password to one of the attacker's choosing.

    The script demonstrates the ability to delete files, reset the admin
    password to the attacker's choosing and upload files (including a
    command prompt).

    The exploit is for educational purposes only.

    To prevent this exploit change the line in comment_delete_cgi.php
    from $logged_in = logged_in( false, true );
    to $logged_in = logged_in( true, true );

    Sincerely,
    'ken'@FTU
    Kenneth F. Belva, CISSP
    http://www.ftusecurity.com

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: yahoo123456_at_hushmail.com: "[Full-disclosure] The Wireless Networking Excuse"

    Relevant Pages

    • SecurityFocus Microsoft Newsletter #83
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability ... Microsoft Internet Explorer History List Script Injection ... Microsoft Windows 2000 Lanman Denial of Service Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #84
      ... The most critical piece of vulnerability assessment is remediation. ... MICROSOFT VULNERABILITY SUMMARY ... IcrediBB Script Injection Vulnerability ... WorkforceROI XPede Unprotected Administrative Facilities... ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #91
      ... SecurityFocus Microsoft Newsletter #91 ... Multiple Bugzilla Security Vulnerabilities ... Geeklog pid CGI Variable SQL Injection Vulnerability ... Geeklog Calendar Event Form Script Injection Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #109
      ... MICROSOFT VULNERABILITY SUMMARY ... PHPRank Banner Script Code Injection Vulnerability ... PHPNuke Multiple Script Code Filtering Vulnerabilities ...
      (Focus-Microsoft)
    • HP Web JetAdmin vulnerabilities.
      ... this vulnerability is not a critical risk. ... Luckily these directories do not have execute permissions but, this script, ... create files in the Administrators startup folder. ... it may be possible to directly inject the hts scripting ...
      (Bugtraq)