PHP Nuke 'user.php' Form Element Substitution Vulnerabilty
BID:3107
Info
PHP Nuke 'user.php' Form Element Substitution Vulnerabilty
| Bugtraq ID: | 3107 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2001 12:00AM |
| Updated: | Jul 27 2001 12:00AM |
| Credit: | This vulnerability was discovered by dinopio and submitted to BugTraq on July 27th, 2001 by MegaHz <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 5.0 |
| Not Vulnerable: | |
Exploit / POC
PHP Nuke 'user.php' Form Element Substitution Vulnerabilty
This example was provided by MegaHz <[email protected]>:
(if the form element of an avatar image equals:)
http://www.target.com/../../../dir_on_server/anyfile.ext
It will load the file when the user info of the attacker is viewed.
This example was provided by MegaHz <[email protected]>:
(if the form element of an avatar image equals:)
http://www.target.com/../../../dir_on_server/anyfile.ext
It will load the file when the user info of the attacker is viewed.
References
PHP Nuke 'user.php' Form Element Substitution Vulnerabilty
References:
References:
- PHP-Nuke Product Page (Francisco Burzi)