Exploit Nuked-klaN 1.3 - Remote Information Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22277
Проверка EDB
  1. Пройдено
Автор
GREGORY LE BRAS
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2003-1371
Дата публикации
2003-02-23
Код:
source: https://www.securityfocus.com/bid/6917/info

A vulnerability has been discovered in Nuked-Klan which may be exploited to execute certain PHP functions on a target server. This issue occurs in the 'Team', 'News', and 'Lien' modules and is due to insufficient sanitization of user-supplied URI parameters.

This issue may be exploited by a remote attacker to obtain sensitive server information, which could aid in launching further attacks against a target system.

The vulnerability was reported for Nuked-Klan beta 1.3; earlier versions may also be affected. 

http://www.example.org/index.php?file=Team&op=phpinfo
http://www.example.org/index.php?file=News&op=phpinfo
http://www.example.org/index.php?file=Liens&op=phpinfo
 
Источник
www.exploit-db.com

Похожие темы