Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or PhpNuke?Need help customizing or designing scripts?Please contact me via the Contact Us option for further details and pricing.
IMPACT: Security Bypass, Exposure of sensitive information, System access
SOFTWARE: Hot or Not Clone - http://secunia.com/product/17082/
DESCRIPTION: RoMaNcYxHaCkEr has reported some vulnerabilities in Hot or Not Clone, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, or to compromise a vulnerable system.
1) Access to control/backup/backup.php is not properly checked, which can be exploited to download database backups and to e.g. disclose the password of the administrative user.
2) The file type of uploaded files is not properly verified in control/sitebanners/upload_banners.php before the file is being stored in a web-accessible directory. This can be exploited to upload arbitrary files (e.g. PHP files).
3) Access to control/sitebanners/upload_banners.php is not properly checked, which can be exploited to e.g. upload and execute arbitrary PHP code.
SOLUTION: Restrict access to the "control" and the "backup" directory (e.g. via a ".htaccess" file).
PROVIDED AND/OR DISCOVERED BY: RoMaNcYxHaCkEr
ORIGINAL ADVISORY: http://milw0rm.com/exploits/4804
Posted on Friday, January 04, 2008 @ 19:23:23 EST by Raven