what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Advisory-16.txt

Advisory-16.txt
Posted Feb 22, 2006
Authored by Paisterist | Site neosecurityteam.net

Invision Power Board 2.1.4 Multiple Full Path Disclosure Vulnerabilities.

tags | advisory, vulnerability
SHA-256 | afc8b5d91c94d44473b65e19fa3da4a01a1ee7b049738c05208ffbd89108b14d

Advisory-16.txt

Change Mirror Download
/*
--------------------------------------------------------
[N]eo [S]ecurity [T]eam [NST]® - Advisory #16 - 18/02/06
--------------------------------------------------------
Program: Invision Power Board 2.1.4
Homepage: https://www.invisionboard.com
Vulnerable Versions: 2.1.4 & Lower versions
Risk: Low Risk!!
Impact: Multiple Vulnerabilities.

-==Invision Power Board 2.1.4 Multiple Vulnerabilities==-
---------------------------------------------------------

- Description
---------------------------------------------------------
Invision Power Board, an award-winning scaleable bulletin
board system, allows you to effortlessly build, manage and
promote your online community. Advanced yet intuitive features
like multi-moderation allow you to focus on developing your
community, rather than wrestling with complex settings.

- Tested
---------------------------------------------------------
localhost & many forums

- Explotation
---------------------------------------------------------
-==Multiple Full Path Disclosure Vulnerabilities==-

ips_kernel/PEAR/Text/Diff/Renderer/inline.php
ips_kernel/PEAR/Text/Diff/Renderer/unified.php
ips_kernel/PEAR/Text/Diff3.php
ips_kernel/class_db.php
ips_kernel/class_db_mysql.php
ips_kernel/class_xml.php
sources/sql/mysql_admin_queries.php
sources/sql/mysql_extra_queries.php
sources/sql/mysql_queries.php
sources/sql/mysql_subsm_queries.php
sources/acp_loaders/acp_pages_components.php
sources/action_admin/member.php
sources/action_admin/paysubscriptions.php
sources/action_public/login.php
sources/action_public/messenger.php
sources/action_public/moderate.php
sources/action_public/paysubscriptions.php
sources/action_public/register.php
sources/action_public/search.php
sources/action_public/topics.php
sources/action_public/usercp.php
sources/classes/bbcode/class_bbcode.php
sources/classes/bbcode/class_bbcode_legacy.php
sources/classes/editor/class_editor_rte.php
sources/classes/editor/class_editor_std.php
sources/classes/post/class_post.php
sources/classes/post/class_post_edit.php
sources/classes/post/class_post_new.php
sources/classes/post/class_post_reply.php
sources/components_acp/registration_DEPR.php
sources/handlers/han_paysubscriptions.php
sources/lib/func_usercp.php
sources/lib/search_mysql_ftext.php
sources/lib/search_mysql_man.php
sources/loginauth/convert/auth.php.bak
sources/loginauth/external/auth.php
sources/loginauth/ldap/auth.php


-==Multiple Directory Listing Vulnerabilities==-

sources/loginauth/convert/
sources/portal_plugins/
cache/skin_cache/cacheid_2/
ips_kernel/PEAR/
ips_kernel/PEAR/Text/
ips_kernel/PEAR/Text/Diff/
ips_kernel/PEAR/Text/Diff/Renderer/
style_images/1/folder_rte_files/
style_images/1/folder_js_skin/
style_images/1/folder_rte_images/
upgrade/*/

The directory listing are not relevant, but with the full path disclosures you can get the path of the forum into the server.

- References
--------------------------------------------------------
https://neosecurityteam.net/advisories/Advisory-16.txt
https://neosecurityteam.net/index.php?action=advisories&id=16

- Solution
--------------------------------------------------------
Not yet, don't worry, this is no very unsecure.


- Credits
-------------------------------------------------
Discovered by Paisterist <paisterist.nst@gmail.com>

[N]eo [S]ecurity [T]eam [NST]® - https://neosecurityteam.net/

Got Questions? https://neosecurityteam.net/foro/


- Greets
--------------------------------------------------------
HaCkZaTaN
Daemon21
K4P0
Link
LINUX
erg0t

And the latin people

@@@@'''@@@@'@@@@@@@@@'@@@@@@@@@@@
'@@@@@''@@'@@@''''''''@@''@@@''@@
'@@'@@@@@@''@@@@@@@@@'''''@@@
'@@'''@@@@'''''''''@@@''''@@@
@@@@''''@@'@@@@@@@@@@''''@@@@@
*/

/* EOF */
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close