SECUNIA ADVISORY ID: SA28261
VERIFY ADVISORY: http://secunia.com/advisories/28261/
CRITICAL: Highly critical
IMPACT: Security Bypass, Exposure of sensitive information, System access
SOFTWARE: Hot or Not Clone - http://secunia.com/product/17082/
DESCRIPTION: RoMaNcYxHaCkEr has reported some vulnerabilities in Hot or Not Clone, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, or to compromise a vulnerable system.
1) Access to control/backup/backup.php is not properly checked, which can be exploited to download database backups and to e.g. disclose the password of the administrative user.
2) The file type of uploaded files is not properly verified in control/sitebanners/upload_banners.php before the file is being stored in a web-accessible directory. This can be exploited to upload arbitrary files (e.g. PHP files).
3) Access to control/sitebanners/upload_banners.php is not properly checked, which can be exploited to e.g. upload and execute arbitrary PHP code.
SOLUTION: Restrict access to the "control" and the "backup" directory (e.g. via a ".htaccess" file).
PROVIDED AND/OR DISCOVERED BY: RoMaNcYxHaCkEr
ORIGINAL ADVISORY: http://milw0rm.com/exploits/4804
Hot or Not Clone Multiple VulnerabilitiesPosted on Friday, January 04, 2008 @ 18:23:23 CST in Security |