Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

logahead UNU edition 1.0 Remote File Upload & code execution

Subject: logahead UNU edition 1.0 Remote File Upload & code execution
Date: 25 Dec 2006 21:13:38 -0000
-=[--------------------ADVISORY-------------------]=-
                                              
              logahead UNU edition 1.0     
                                               
  Author: CorryL    [corryl80@gmail.com]   
-=[-----------------------------------------------]=-


-=[+] Application:    logahead UNU edition
-=[+] Version:        1.0
-=[+] Vendor's URL:   http://typo.i24.cc/logahead/ 
-=[+] Platform:       Windows\Linux\Unix
-=[+] Bug type:       Remote Upload file & Code execution
-=[+] Exploitation:   Remote
-=[-]
-=[+] Author:          CorryL  ~ corryl80[at]gmail[dot]com ~
-=[+] Reference:       www.x0n3-h4ck.org
-=[+] Virtual Office:  http://www.kasamba.com/CorryL
-=[+] Irc Chan:        irc.darksin.net #x0n3-h4ck        
-=[+] Special Thanks: Merry Christmas for All, Thanks for all  #x0n3-h4ck 
member, 
                                  un saluto a tutti gli avolesi nel mondo.


..::[ Descriprion ]::..

You might already have heard of logahead - the ajaxified blogging engine using 
PHP4 and mySQL database by James from the UK.
The UNU edition is based on the logahead beta 1.0 code published under GNU/GPL 
license. While the original version sticks to the basic functions of a blog 
(mainly publishing posts and receiving comments), the UNU edition is more 
enchanted and offers a number of additional features.


..::[ Bug ]::..

My give searches the form Widgets of this blog is results vulnerability, in fact
a remote attaker is able to upload also a file php, and to perform arbitrary 
commands
inside the server victim.

..::[ Proof Of Concept ]::..

http://www.server-victim/extras/plugins/widged/_widged.php?A=U&D= 


..::[ Disclousure Timeline ]::..

 [25/12/2006] - Public disclousure

<Prev in Thread] Current Thread [Next in Thread>
  • logahead UNU edition 1.0 Remote File Upload & code execution, corrado . liotta <=