Bugtraq mailing list archives
Re: PHPNuke viewpage.php allows Remote File retrieving
From: DaiTengu <daitengu () war-ensemble com>
Date: Tue, 25 Mar 2003 11:59:26 -0600
Zero_X www.lobnan.de Team wrote:
umm, what version of phpNuke is vulnerable to this? as far as I'm aware, there has not been any viewpage.php since before 5.0...viewpage.php is a part of PHPNuke. The Script allows an attacker to view all files on the System. Example: http://server.com/viewpage.php?file=/etc/passwd
I beleive this was reported then as well. reguardless, this is not true with 6.0 -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Mike "DaiTengu" Miller UA Site Coordinator: http://www.unitedadmins.com Webmaster: http://war-ensemble.com Sysop: telnet://bbs.war-ensemble.com StatsMe Team: http://www.unitedadmins.com/StatsMe.php -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Current thread:
- PHPNuke viewpage.php allows Remote File retrieving Zero_X www . lobnan . de Team (Mar 25)
- Re: PHPNuke viewpage.php and another SQL injections Tibor Pittich (Mar 25)
- Re: PHPNuke viewpage.php allows Remote File retrieving DaiTengu (Mar 25)
- Re: PHPNuke viewpage.php allows Remote File retrieving Jim Geovedi (Mar 25)
- Re: PHPNuke viewpage.php allows Remote File retrieving Christopher Warner (Mar 26)
- Re: PHPNuke viewpage.php allows Remote File retrieving Tonu Samuel (Mar 26)
- Re: PHPNuke viewpage.php allows Remote File retrieving Jim Geovedi (Mar 25)
- <Possible follow-ups>
- Re: PHPNuke viewpage.php allows Remote File retrieving admin (Mar 26)
- Re: PHPNuke viewpage.php allows Remote File retrieving Kevin (Mar 27)
- Re: PHPNuke viewpage.php allows Remote File retrieving admin (Mar 27)