Hot or Not Clone Multiple Vulnerabilities

Posted on Friday, January 04, 2008 @ 19:23:23 UTC in Security
by Raven

SECUNIA ADVISORY ID: SA28261

VERIFY ADVISORY: http://secunia.com/advisories/28261/

CRITICAL: Highly critical

IMPACT: Security Bypass, Exposure of sensitive information, System access

SOFTWARE: Hot or Not Clone - http://secunia.com/product/17082/

DESCRIPTION: RoMaNcYxHaCkEr has reported some vulnerabilities in Hot or Not Clone, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, or to compromise a vulnerable system.

1) Access to control/backup/backup.php is not properly checked, which can be exploited to download database backups and to e.g. disclose the password of the administrative user.

2) The file type of uploaded files is not properly verified in control/sitebanners/upload_banners.php before the file is being stored in a web-accessible directory. This can be exploited to upload arbitrary files (e.g. PHP files).

3) Access to control/sitebanners/upload_banners.php is not properly checked, which can be exploited to e.g. upload and execute arbitrary PHP code.

SOLUTION: Restrict access to the "control" and the "backup" directory (e.g. via a ".htaccess" file).

PROVIDED AND/OR DISCOVERED BY: RoMaNcYxHaCkEr

ORIGINAL ADVISORY: http://milw0rm.com/exploits/4804
 
 
click Related        click Share
 
News ©

Site Info

Last SeenLast Seen
  • vashd1
  • rovshan
Server TrafficServer Traffic
  • Total: 483,432,356
  • Today: 39,504
Server InfoServer Info
  • May 12, 2024
  • 09:41 pm UTC