lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Wed, 30 Nov 2005 10:01:07 -0500 (EST)
From: Paul Laudanski <zx@...tlecops.com>
To: retrogod@...ceposta.it
Cc: bugtraq@...urityfocus.com
Subject: Re: Xaraya <= 1.0.0 RC4 D.O.S / file corruption


On 29 Nov 2005 retrogod@...ceposta.it wrote:

> Xaraya <= 1.0.0 RC4 D.O.S / file corruption
> 
> software:
> site: http://www.xaraya.com
> description: "Xaraya 1.0 Core is an Open Source web application framework
> written in PHP"
> i) you can create an empty dir, in some cases this leads to D.O.S. condition,poc:
> 
> http://[target]/[path_to_xaraya]/index.php?module=../../../../.key.php
> http://[target]/[path_to_xaraya]/index.php?module=../../../../../.htaccess

Being that Xaraya is a fork from Post nuke which is a fork off PHP Nuke 
the input would already have been checked for directory traversal among 
other things.

-- 
Paul Laudanski, Microsoft MVP Windows-Security
[de] http://de.castlecops.com
[en] http://castlecops.com
[wiki] http://wiki.castlecops.com



Powered by blists - more mailing lists