about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , LS simple guestbook (v1) Remote Code Execution Vulnerability




2007-04-15 LS simple guestbook (v1) Remote Code Execution Vulnerability
Rated as : High Risk

########################################################
#   Special Greetings To - Timq,Warpboy,The-Maggot     #
########################################################

File: index.php
Affects: LS simple guestbook (v1)
Date: 15th April 2007

Issue Description:
===========================================================================
LS simple guestbook fails to sanitize user input that it writes to the
posts.txt file when the user leaves a message, this file is then included
causing any php code within it to be run.
===========================================================================

Scope:
===========================================================================
An attacker can inject arbitrary php code and potentially execute
commands
on the system.
===========================================================================

Recommendation:
===========================================================================
Add the following line of code in index.php:

$message = strip_tags($message);

just above:

if ($message != "") {$file =
fopen("$dataf","a");
===========================================================================


Example:

name = Test
message = <?php phpinfo(); ?>


Discovered By: Gammarays

securitydot.net - 2007-04-15

Advertising

Copyright 2007, SecurityDot
Sun, 22 Nov 2009 03:56:44 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Sex photos www.social www.pakist 200 /compo 2005 phpBB australia Www.dubais SimpleBoar Www.girt19 fara sex arab f Film india six girl cops www.liu-la www.cha100 /search/ex Www memek vBulletin julia prez My_eGaller www.redian xoops modu www.yuecu. web wiz f voir extra d..._Stand AVIzon Free+India SEXY IMEAG www.cnsyb. live sex c VIDEO SEX www.india Laxpionsex news/explo Apache 1.3 txt.liuxin http://3g7 Exploits S Crack Data www.chg88. www.gamejd ranimukher trisa dcl Www.Sexy p myphpadmin apache2.pl Sexylady.c