No account yet?
Home » HSC Research » Advisories » [HSC] B2evolution Blog Directory Disclosure Vulnerability
[HSC] B2evolution Blog Directory Disclosure Vulnerability E-mail
HSC Research Group - Advisories
Written by Hackers Center   
Sunday, 06 May 2007 18:48
[HSC] b2evolution Blog Directory Disclosure Vulnerability

b2evolution is a free blog tool for the next generation of blogs. An attacker can see what files are in the Directory. Knowing what is there to be executed can allow for more targeted and intelligent attacks against PHP Files known to be vulnerable listed there. A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.




Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz


Remote: YES
Class: Improper Instalation configuration.




http://b2evolution.net/
Version: 1.9.3



* Attackers can exploit these issues via a web client. Also possible HTML injection in post.


Exploit:


http://www.site.com/v-1-9/blogs/inc/_misc/
http://www.site.com/Path/inc/_misc/
http://www.site.com/blog/inc/_misc/


Path Disclosure:

- http://site.com/path/blogs/admin.php?ctrl=files&root="

- var/www/web7/web/v-1-9/blogs/inc/MODEL/files/_filerootcache.class.php on line 64



Full Directory Listing:

http://evocms.cvs.sourceforge.net/evocms/b2evolution/blogs/inc/


Proff of Concept: http://i10.tinypic.com/4zabxjr.jpg



Only becoming a hacker you can stop a hacker. Were can you learn with out having to pay thousands?- http://kit.hackerscenter.com/ - The most comprehensive security pack you will ever find on the net!
 

Security Services by HSC