PostNuke

Flexible Content Management System

News

New PHP-Nuke Security Alert

Contributed by Anonymous on Sep 25, 2001 - 08:19 PM

From the report:












"twlc security divison






24/09/2001












Php nuke BUGGED.












Found by:






LucisFero and supergate






./twlc












Summary






This time the bug is really dangerous...it allows you to 'cp' any file on






the box... or even upload files...












Systems Affected






all the versions ARE vulnerable






except '5.0 RC1' (i wonder why a released c. is ok while the final 5.2 is






bugged)..."
1100