Go Back   Website Hosting - VPS Hosting - Domain Registration Ireland :: Blacknight > Technical Support > Security Notices
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 17-08-05, 03:36 PM
Junior Member
 
Join Date: May 2004
Posts: 18
Default phpAdsNew Multiple Vulnerabilities

Some vulnerabilities have been reported in phpAdsNew, which can be exploited by malicious people to disclose certain sensitive information, conduct SQL injection attacks, or compromise a vulnerable system.

1) A vulnerable version of XML-RPC for PHP was used.

2) Input passed to the "clientid" parameter in lib-view-direct.inc.php isn't properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Successful exploitation requires MySQL 4.1+ or PostgreSQL.

3) Input passed to certain parameters isn't properly verified before being used to include files. This can be exploited to include arbitrary local files.

Solution:
Update to version 2.0.6.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
phpAdsNew XML-RPC PHP Code Execution Vulnerability niall Security Notices 0 01-07-05 10:05 AM
Drupal PHP Code Execution Vulnerabilities niall Security Notices 0 30-06-05 11:00 AM
Xoops Cross-Site Scripting and SQL Injection Vulnerabilities niall Security Notices 0 30-06-05 10:55 AM
Wordpress Multiple Vulnerabilities niall Security Notices 0 30-06-05 10:54 AM


All times are GMT. The time now is 08:32 PM.


VPS Hosting Web Hosting Ireland Blacknight Blog Blacknight Status

Powered by: vBulletin Version 3.6.8, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Blacknight 2005 - 2008 | VPS Hosting

SEO by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17