Go Back   Website Hosting - VPS Hosting - Domain Registration Ireland :: Blacknight > Technical Support > Security Notices

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 20-10-05, 08:28 PM
Administrator
Site Admin
 
Join Date: Aug 2003
Location: Ireland
Posts: 366
Send a message via ICQ to blacknight Send a message via AIM to blacknight Send a message via MSN to blacknight Send a message via Skype™ to blacknight
Default PHP-Nuke NukeFixes Addon "file" Local File Inclusion Vulnerability

A vulnerability has been discovered in the NukeFixes addon for PHP-Nuke, which can be exploited by malicious people to disclose sensitive information.

Input passed to the "file" parameter in "modules.php" isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from local resources.

Successful exploitation requires that "magic_quotes_gpc" is disabled.

The vulnerability has been confirmed in version 3.1 for PHP-Nuke 7.8. Other versions may also be affected.

Solution:
Edit the source code to ensure that input is properly verified.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
addon, file, inclusion, local, nukefixes, phpnuke, vulnerability

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 02:15 PM.


VPS Hosting Web Hosting Ireland Blacknight Blog Blacknight Status

Powered by: vBulletin Version 3.7.3, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Blacknight 2005 - 2008 | VPS Hosting

SEO by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17