------------------------------------------------------------ - EXPL-A-2005-012 exploitlabs.com Advisory 041 - ------------------------------------------------------------ - PHP TopSites - AFFECTED PRODUCTS ================= PHP TopSites FREE PHP TopSites PRO http://itop10.net OVERVIEW ======== PHP TopSites is a PHP/MySQL-based customizable TopList script DETAILS ======= 1. Information Disclosure The setup / admin section (admin control panel) can be accessed without authorization. This exposes the administrative mysql info including user-db-pass-host and admin email addresses. Further access allows reading / editing of toplist member info including the above data. POC === 1. ------ The configuration of the top lists in the admin area can be accessed by the following URL: http://[host]/[toplistdirectory]/[admindirectory]/setup.php SOLUTION: ========= vendor contact: roman@itop10.net June 18, 2005 1st notification roman@itop10.net June 19, 2005 Vendor reply response: admin directory should be .htaccess protected roman@itop10.net June 19, 2005 Researcher reply response: this is not satisfactory roman@itop10.net June 21, 2005 response: i will fix it as soon as possible roman@itop10.net July 7 roman@itop10.net July 13 no response(s) recieved ( itop10.net ) appears down Credits ======= This vulnerability was discovered and researched by h4cky0u of http://www.h4cky0u.org h4cky0u at gmail.com and Donnie Werner of exploitlabs Donnie Werner mail: wood at exploitlabs.com mail: morning_wood at zone-h.org -- web: http://exploitlabs.com web: http://zone-h.org