El dj 31 de 03 de 2011 a les 12:55 +0200, en/na mougeyc va escriure:
> Hi everyone !
> 
> It's my first mail on this mailing list, I hope I could help you :)
> 
> In the file : apertium/webspace/index.php
> <?php 
>               $headerFile = "content/" . $lang . "/header.html";
>               if( file_exists($headerFile) ) {
>                       include_once($headerFile);
>               } else {
>                       include_once("content/en/header.html");
>               }
>       ?>
> 
> Cause to "register_global", you can give variable by URL ( here $lang ).
> You can finish your string with the null byte code ( \0, %00 ). It cuts
> the
> $headerFile, and doesn't add "/header.html" to the end.
> So, for example,
> http://www.apertium.org/?id=whatisapertium&lang=../images/langiconclassic_r9_c24.png
> will include the "code" of the picture /langiconclassic_r9_c24.png (safety
> example, of course :) )
> 
> In addition, because this variable is show without any filter, you can use
> "XSS attacks". It's like this safety example :
> http://www.apertium.org/?id=whatisapertium&lang=%22%3E%3Cscript%3Ealert%28%22XSS%22%29;%3C/script%3E
> 
> I think there several times this problem in *.php files.
> 
> Thanks for attention,
> Regards,
> Mougey Camille(commial) ([email protected])

Thanks for the heads up! We're currently trying to change our web to one
based on Wordpress, I hope it will be ready before someone takes
advantage of the exploit :)

Fran


------------------------------------------------------------------------------
Create and publish websites with WebMatrix
Use the most popular FREE web apps or write code yourself; 
WebMatrix provides all the features you need to develop and 
publish your website. http://p.sf.net/sfu/ms-webmatrix-sf
_______________________________________________
Apertium-stuff mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/apertium-stuff

Reply via email to