what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

cutenews136.txt

cutenews136.txt
Posted Aug 31, 2004
Authored by e0r

Cute news versions 1.3.6 and below have a world writable news.txt file that allows for site defacement.

tags | advisory
SHA-256 | 888f182df2b68a165e3e0b213cb4ae41f1446894967a95da68b89f850e712485

cutenews136.txt

Change Mirror Download


Date: August 29, 2004
Vender: http://www.cutephp.com/
Program: CuteNews
Versions affected: => 1.3.6
Bug: CuteNews News.txt writable to world
Type:
Author: e0r
www: http://www.rootthief.com/
team: !Sui-Generes (!Sui)
Email: homicidal @ gmail . com
-----------------------------

>Discription:
Cute news is a powerful and easy for using news management system that use flat files to store its database. It supports comments, archives, search function, image uploading, backup function, IP banning, flood protection ...
----------------

>Vulnerability:
CuteNews is a very very popular news management system which makes this all the more serious. The folder "Data" is chmod '777', it has to be for CuteNews to work. But this poses a problem, if it is chmod 777 it means ANYONE can write to it. What makes it even worse is that the news.txt file is stored there, so anyone with local access to the file can open it up and replace something like:

||e0r|Open.|Many updates to come. For now, enojy the Forums.|||||

with

||!Sui|HACKED.|U got hexored!!1|||||

And now the vulnerable CuteNews is now defaced.


---------------

>Fix:
I haven't attempted to fix it, I'll leave that up to the vendor.
---------------

>Greets: !Sui-Generis, #sui @ efnet, #blackhats,
#phiral, atomix, d3thstar, m00, mgrd,
lost-buffer, drug5t0r3, rootthief.com
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close