[VIM] [bogus] Re: V [r.5.7 at hotmail.com: Gallery <= 1.4.4-pl4 (phpbb_root_path) Remote File Include Vulnerability] (fwd)

rkeith at securityfocus.com rkeith at securityfocus.com
Tue Jan 16 13:18:29 EST 2007


---------- Forwarded message ----------
Date: Tue, 16 Jan 2007 10:11:26 -0700 (MST)
From: pjungles at securityfocus.com
Subject: [bogus] Re: V [r.5.7 at hotmail.com: Gallery <= 1.4.4-pl4
     (phpbb_root_path) Remote File Include Vulnerability] (fwd)


    Install checks for register_global on and magic quotes...
   The script set it to  $phpbb_root_path = "./" before including.

   New version as well as the version reported vuln.

   PJ


> 
> ----- Forwarded message from me you <r.5.7 at hotmail.com> -----
> 
> From: "me you" <r.5.7 at hotmail.com>
> Subject: Gallery <= 1.4.4-pl4 (phpbb_root_path) Remote File Include 
> Vulnerability
> To: submit at milw0rm.com
> Cc: bugtraq at securityfocus.com
> Date: Tue, 16 Jan 2007 13:52:57 +0000
> Message-ID: <BAY20-F166F1094AC99773C87BF2EBFB40 at phx.gbl>
> 
> =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
> 
> Gallery <= 1.4.4-pl4 (phpbb_root_path) Remote File Include Vulnerability
> 
> Script : Gallery
> 
> Version : 1.4.4-pl4
> 
> URL :
> http://puzzle.dl.sourceforge.net/sourceforge/gallery/gallery-1.6-alpha3.tar.gz
> 
> Author : BorN To K!LL
> 
> =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
> 
> Code in :.    contrib/phpBB2/modules.php
>
> 	include_once($phpbb_root_path . 'extension.inc');
> 	include_once($phpbb_root_path . 'common.'.$phpEx);
> 	include_once($phpbb_root_path . 'includes/functions.'.$phpEx);
> 
> =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
> 
> Explo!t :.
> ^^^^^
> www.site.com/[path]/contrib/phpBB2/modules.php?phpbb_root_path=shellcode.txt?
> 
> =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
> 
> GreeTz to :  Dr.2  ,  Asbmay  ,  General C  ,  ToOoFa  ,  SHiKaA  ,  str0ke
> ...
> 
> =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
> 
> _________________________________________________________________
> Don't just search. Find. Check out the new MSN Search!
> http://search.msn.click-url.com/go/onm00200636ave/direct/01/
> 
> 
> ----- End forwarded message -----
>

--
Rob Keith
Symantec


More information about the VIM mailing list