about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , LS simple guestbook (v1) Remote Code Execution Vulnerability




2007-04-15 LS simple guestbook (v1) Remote Code Execution Vulnerability
Rated as : High Risk

########################################################
#   Special Greetings To - Timq,Warpboy,The-Maggot     #
########################################################

File: index.php
Affects: LS simple guestbook (v1)
Date: 15th April 2007

Issue Description:
===========================================================================
LS simple guestbook fails to sanitize user input that it writes to the
posts.txt file when the user leaves a message, this file is then included
causing any php code within it to be run.
===========================================================================

Scope:
===========================================================================
An attacker can inject arbitrary php code and potentially execute
commands
on the system.
===========================================================================

Recommendation:
===========================================================================
Add the following line of code in index.php:

$message = strip_tags($message);

just above:

if ($message != "") {$file =
fopen("$dataf","a");
===========================================================================


Example:

name = Test
message = <?php phpinfo(); ?>


Discovered By: Gammarays

securitydot.net - 2007-04-15

Advertising

Copyright 2007, SecurityDot
Sun, 22 Nov 2009 10:42:54 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
IIS Direct sex gilrl Courier Im 200 /compo www.600bb. indian big sexadult p Rlogin+%25 film sex x www.inteke www.89ar.c gallery 2 www.wendy. www.slende elephantli news for c OpenSSL 0. IceWarp We ashwariya TemplatePo Cisco Unif ww.porn.co www.xdream kajalagarw searching www.yesge. www.zgzpl. Www.parsee news for c appache ss trisa sex. sex2005 jendeh sex vhdo nayanathar www.bnzx.z Www.datpif Freesexywa Apache 2.0 trisa sex. touxian.5d teddy fact aslampop20 astaravist phorum 5.2 Fucking in Hinata bug ARTIS INDI Www.vidio news for c