PHP-Nuke Addressbook Module *module_name* Local File Inclusion

Posted on Friday, April 06, 2007 @ 10:50:32 PDT in Security
by Raven

SECUNIA ADVISORY ID: SA24697

VERIFY ADVISORY: http://secunia.com/advisories/24697/

CRITICAL: Moderately critical

IMPACT: Exposure of system information, Exposure of sensitive information

WHERE: >From remote

SOFTWARE: Addressbook 1.x (module for PHP-Nuke) - http://secunia.com/product/13832/

DESCRIPTION: bd0rk has discovered a vulnerability in the Addressbook module for PHP-Nuke, which can be exploited by malicious people to disclose sensitive information.

Input passed to the "module_name" parameter in modules/Addressbook/addressbook.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources. Successful exploitation requires that "register_globals" is enabled, "magic_quotes_gpc" is disabled, and that the system is running PHP5. The vulnerability is confirmed in version 1.2. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly verified.

PROVIDED AND/OR DISCOVERED BY: bd0rk

ORIGINAL ADVISORY: http://milw0rm.com/exploits/3582
 
 
click Related        click Share
 
News ©

Site Info v2.2.2

Last SeenLast Seen
Server TrafficServer Traffic
  • Total: 346,438,749
  • Today: 42,338
Server InfoServer Info
  • Jan 23, 2018
  • 08:09 pm PST
 
 

Daily Inspiration