exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

manpage.txt

manpage.txt
Posted Jan 11, 2004
Authored by Cabezon Aurelien | Site isecurelabs.com

The PHP class _Manpage Lookup_ is vulnerable to a directory traversal bug due to a lack of input validation.

tags | exploit, php
SHA-256 | 7755ca5dd6ea60fc0ee416787fc1da2b9826689ee6413b1dbc16b268fd7834a9

manpage.txt

Change Mirror Download
Hi ppl,

_Manpage Lookup_ is a PHP class that helps you to build a "manpage"
frontend in php. It is powered by Andy (http://php.amnuts.com).

The script _class.manpagelookup.php_ was vulnerable to a directory
transversal bug (because of leaks is input validation) that could lead
to disclose any readable (by the httpd process id) files on the remote
server.

The problem was located in the function buildManPage(), the $cmd
variable was not filtered enough and the path of any file to open could
be given across the user input.

Exploiting this issue was easy:
http://www.foo.com/manpage/index.php?command=/etc/resolv.conf

The vulnerability has now been fixed by Andy. All people who are running
this script should upgrade asap (http://php.amnuts.com).

Best regards,

--
Cabezon Aurélien <aurelien.cabezon@isecurelabs.com>
iSECURELABS.COM - http://www.isecurelabs.com
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close