PHP-Nuke Addressbook Module *module_name* Local File Inclusion

Posted on Friday, April 06, 2007 @ 09:50:32 UTC in Security
by Raven

SECUNIA ADVISORY ID: SA24697

VERIFY ADVISORY: http://secunia.com/advisories/24697/

CRITICAL: Moderately critical

IMPACT: Exposure of system information, Exposure of sensitive information

WHERE: >From remote

SOFTWARE: Addressbook 1.x (module for PHP-Nuke) - http://secunia.com/product/13832/

DESCRIPTION: bd0rk has discovered a vulnerability in the Addressbook module for PHP-Nuke, which can be exploited by malicious people to disclose sensitive information.

Input passed to the "module_name" parameter in modules/Addressbook/addressbook.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources. Successful exploitation requires that "register_globals" is enabled, "magic_quotes_gpc" is disabled, and that the system is running PHP5. The vulnerability is confirmed in version 1.2. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly verified.

PROVIDED AND/OR DISCOVERED BY: bd0rk

ORIGINAL ADVISORY: http://milw0rm.com/exploits/3582
 
 
click Related        click Share
 
News ©

Site Info

Last SeenLast Seen
  • Jonnie5373
  • vashd1
Server TrafficServer Traffic
  • Total: 482,551,776
  • Today: 30,673
Server InfoServer Info
  • Apr 26, 2024
  • 10:17 pm UTC