PHP Web Host - Quality Web Hosting For All PHP Applications Clan Themes! We make clans look good!!
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.
Author Message
chatserv
The Mouse Is Extension Of Arm


Joined: May 02, 2003
Posts: 1396
Location: Puerto Rico

PostPosted: Mon May 03, 2004 8:40 am Reply with quote Back to top

XSS and full path disclosure in PhpNuke Reported by waraxe.

Open all files (except .htaccess and index.html) contained in admin/links and add the following right after the file credits:

Code:
if (!eregi("admin.php", $_SERVER['PHP_SELF'])) { die ("Access Denied"); }


Open modules/Statistics/index.php and find:
Code:
$pagetitle = "- "._STATS."";

Right below that line add:
Code:
if (isset($year)) {
    $year = intval($year);
}



The patches have yet to be updated so apply these manually, i will update them ASAP, my thanks to Sting for the heads up.
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon May 03, 2004 9:05 am Reply with quote Back to top

Thanks Sting and Chatserv!
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
chatserv
The Mouse Is Extension Of Arm


Joined: May 02, 2003
Posts: 1396
Location: Puerto Rico

PostPosted: Mon May 03, 2004 9:07 am Reply with quote Back to top

Thanks Raven.

Users of the 6.0 patch may need to alter the admin/links line posted above if their php version is old, the line in this case would be:

Code:
if (!eregi("admin.php", $PHP_SELF)) { die ("Access Denied"); }
View user's profile Send private message Visit poster's website
GanjaUK
Life Cycles Becoming CPU Cycles


Joined: Feb 14, 2004
Posts: 633
Location: England

PostPosted: Mon May 03, 2004 9:59 am Reply with quote Back to top

I can sleep easy at night because of your patches chatserv. Shocked
View user's profile Send private message Visit poster's website
ballymuntrev
Hangin' Around


Joined: Mar 22, 2004
Posts: 49

PostPosted: Thu May 06, 2004 5:06 pm Reply with quote Back to top

Yeah thanks m8, I just patched all mine now too Smile
View user's profile Send private message Visit poster's website
Muffin
Client


Joined: Apr 10, 2004
Posts: 649
Location: UK

PostPosted: Sun Aug 01, 2004 5:49 am Reply with quote Back to top

Are these added to the latest patched files download Chat? Or do we have to add them ourselves?

Thanks for keeping us safe
View user's profile Send private message
chatserv
The Mouse Is Extension Of Arm


Joined: May 02, 2003
Posts: 1396
Location: Puerto Rico

PostPosted: Sun Aug 01, 2004 7:28 pm Reply with quote Back to top

Yes they were added.
View user's profile Send private message Visit poster's website
Muffin
Client


Joined: Apr 10, 2004
Posts: 649
Location: UK

PostPosted: Mon Aug 02, 2004 7:09 am Reply with quote Back to top

thank you Chat
View user's profile Send private message
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum