You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 681 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Meta Keywords Module
SecurityLi-Nux writes "Security Advisory about Meta Keywords Module

Together Team s.r.l. Security Advisory

Advisory: PNM00001
Critical Level: Medium
Category: PHP-Nuke
Sub-Category: ADD-ON Module
Attack Type: SQL-Injection
Target: Meta Keywords Module by Prophet (http://musicodezone.com/front/modules.php?name=Downloads&d_op=viewdownload&cid=3)
Found By: Francesco Marasco aka Li-Nux - Together Team s.r.l.

Description:

It's possible from an anonymous user to inject sql instruction to RDBMS by perform:
http://www.domain.com/modules.php?name=Meta_Tags&op=addToMyMeta&tag=&clear=&list=[SQL-INJECTION HERE]

Test:

Before execute proof-of-code exploit:

mysql> select * from nuke_meta;
+---------+
| tags |
+---------+
| PHPNUKE |
+---------+
1 row in set (0.08 sec)

After execute proof-of-code exploit:

mysql> select * from nuke_meta;
+------+
| tags |
+------+
| TEST |
+------+
1 row in set (0.00 sec)
"
Posted on Tuesday, February 01 @ 04:54:57 CET by TogetherTeam
 
Related Links
· Computer Cops
· More about Security
· News by TogetherTeam


Most read story about Security:
PHP-Nuke admin.php security hole - PATCHED

Article Rating
Average Score: 3.66
Votes: 3


Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad


Options

 Printer Friendly Page  Printer Friendly Page

 Send to a Friend  Send to a Friend

Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Meta Keywords Module (Score: 1)
by Prophet on Tuesday, February 01 @ 11:35:34 CET
(User Info | Send a Message) http://jasonlau.biz
Sorry people.
I am working on this as we speak.
There will be a new version availble shortly at the same location.
Thanks for the advisory!

Jae



Re: Meta Keywords Module (Score: 1)
by Prophet on Tuesday, February 01 @ 14:20:25 CET
(User Info | Send a Message) http://jasonlau.biz
In light of this security hole, I have redesigned the Meta Keyword module. The new version is available for download at http://musicodezone.com/front/modules.php?name=Downloads&d_op=viewdownload&cid=3


Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.075 Seconds - 266 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::