Twenty Year Anniversary

postnukePath.txt

postnukePath.txt
Posted Sep 21, 2004
Site mantralab.org

Postnuke 0.750 Phoenix is susceptible to multiple full path disclosure flaws.

tags | advisory
MD5 | 81f4fede96a1e21bb6f737f71ce33b99

postnukePath.txt

Change Mirror Download


#####################################################################
# [CODEBUG Labs] #
# Advisory #6 #
# Title: Multiple Full Disclosure Path in postnuke 0.750 phoenix #
# Author: FAiN182 - fain182@infinito.it #
# Product: Postnuke 0.750 Phoenix #
# Type: Full disclosure path #
# Web: http://www.mantralab.org
# Personal Site: http://fain182.altervista.org #
#####################################################################

---[ the product

Postnuke is a CMS (Contenent Management System) that is an improved
version of php-nuke. You can find it here: http://www.phpnuke.com.

---[ the bug

The pages of the full disclosure path vulnerabilities that are in
the core and in the modules of postnuke are wrote to be included
in other pages, but if you access directly they made a page error
mainly for Unkwon function.


---[ the exploit:

In the core of postnuke you can get an error page visiting this url:

http://www.site_with_postnuke.com/footer.php

In the other modules that are by default in postnuke:

http://www.site_with_postnuke.com/modules/Downloads/admin.php
http://www.site_with_postnuke.com/modules/FAQ/admin.php
http://www.site_with_postnuke.com/modules/Reviews/admin.php
http://www.site_with_postnuke.com/modules/Sections/admin.php
http://www.site_with_postnuke.com/modules/Submit_News/admin.php
http://www.site_with_postnuke.com/modules/Top_List/admin.php
http://www.site_with_postnuke.com/modules/Web_Links/admin.php

---[ the patch

You can protect the page form the direct access as is in the file
header.php, writing this lines at the begin of all the page bugged
in that way:

if (strpos('header.php', $_SERVER['PHP_SELF'])) {
die ("You can't access this file directly...");
}

---[ Greetings

To Mantra, Anat3ma and all CODEBUG project team

---[ EOF ]-----------------------------------------------------------

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

July 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    1 Files
  • 2
    Jul 2nd
    26 Files
  • 3
    Jul 3rd
    15 Files
  • 4
    Jul 4th
    11 Files
  • 5
    Jul 5th
    13 Files
  • 6
    Jul 6th
    4 Files
  • 7
    Jul 7th
    4 Files
  • 8
    Jul 8th
    1 Files
  • 9
    Jul 9th
    16 Files
  • 10
    Jul 10th
    15 Files
  • 11
    Jul 11th
    32 Files
  • 12
    Jul 12th
    22 Files
  • 13
    Jul 13th
    15 Files
  • 14
    Jul 14th
    1 Files
  • 15
    Jul 15th
    1 Files
  • 16
    Jul 16th
    21 Files
  • 17
    Jul 17th
    15 Files
  • 18
    Jul 18th
    15 Files
  • 19
    Jul 19th
    17 Files
  • 20
    Jul 20th
    11 Files
  • 21
    Jul 21st
    1 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close