Ravens PHP Scripts

Hot or Not Clone Multiple Vulnerabilities
Date: Friday, January 04, 2008 @ 19:23:23 PST
Topic: Security


SECUNIA ADVISORY ID: SA28261

VERIFY ADVISORY: http://secunia.com/advisories/28261/

CRITICAL: Highly critical

IMPACT: Security Bypass, Exposure of sensitive information, System access

SOFTWARE: Hot or Not Clone - http://secunia.com/product/17082/

DESCRIPTION: RoMaNcYxHaCkEr has reported some vulnerabilities in Hot or Not Clone, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, or to compromise a vulnerable system.



1) Access to control/backup/backup.php is not properly checked, which can be exploited to download database backups and to e.g. disclose the password of the administrative user.

2) The file type of uploaded files is not properly verified in control/sitebanners/upload_banners.php before the file is being stored in a web-accessible directory. This can be exploited to upload arbitrary files (e.g. PHP files).

3) Access to control/sitebanners/upload_banners.php is not properly checked, which can be exploited to e.g. upload and execute arbitrary PHP code.

SOLUTION: Restrict access to the "control" and the "backup" directory (e.g. via a ".htaccess" file).

PROVIDED AND/OR DISCOVERED BY: RoMaNcYxHaCkEr

ORIGINAL ADVISORY: http://milw0rm.com/exploits/4804






This article comes from Ravens PHP Scripts
http://www.ravenphpscripts.com

The URL for this story is:
http://www.ravenphpscripts.com/modules.php?name=News&file=article&sid=3193