lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20030518101412.20825.qmail@www.securityfocus.com> Date: 18 May 2003 10:14:12 -0000 From: Lorenzo Manuel Hernandez Garcia-Hierro <security@...enzohgh.com> To: bugtraq@...urityfocus.com Subject: PHP-Nuke module PHP-Banner-Exchange path disclosure ------- Product: PHP-Nuke Vendor: F.Burzi Module: PHP-Banner Exchange Version: 1.2 ------- Accessing directly to the PHP Banner Exchange module and without a specified file : http://[target]/modules/phpbannerexchange/ ( phpbannerexchange module directory ) you get this: Warning: main(mainfile.php) [function.main]: failed to create stream: No such file or directory in /home/phpnuke- /public_html/modules/phpbannerexchange/index.php on line 20 Fatal error: main() [function.main]: Failed opening required 'mainfile.php' (include_path='') in /home/phpnuke- /public_html/modules/phpbannerexchange/index.php on line 20 (Paths related your local paths in your server) --------- SOLUTION: --------- Configure your php.ini errors flags or by hand-editing the original module files .