You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 633 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Security Bug in My_eGallery 2.7.9 FIXED!!! READ!!! (Score: 1)
by Laffer on Saturday, November 29 @ 03:53:33 CET
(User Info | Send a Message) http://www.comicfan.de
The bug is easy: The first line of the Module contain

include ("$basepath/somemodule.php");

since basepath will link to the http://someurl/textfile.txt the textfile.txt from another location will be included and therefore executed through the webserver. This textfile.txt contains as you mentioned malicious code, calling the SYSTEM function to execute in /tmp directory of the webserver (and afterwards deleted). But in the / or /tmp you often find some reliquients of other modules, like in my case, a kernel exploit which was uploaded and started this way...


| Parent

Re: Security Bug in My_eGallery 2.7.9 FIXED!!! READ!!! (Score: 1)
by johnnycard on Saturday, November 29 @ 08:37:06 CET
(User Info | Send a Message)
Jeruvys link points for an upgrade for Post Nuke by the looks of it. Is there anyone who could port this fix for PHP Nuke?


| Parent
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.061 Seconds - 193 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::