MemHT Portal is a Free PHP CMS and Blog
It permit the creation and the management online of websites with few and easy steps.
It's completelly customizable, expandable and suitable for all needs.
Moderators: Moderators
Forum RSS feedReply
-! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
AuthorText
mcmxtr
Just arrived
Avatar

Posts: 2
Contributes: 2

Gender: _NEUTRAL_
Online: No
Date: 07/09/2008 10:31
-! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11618
how Fix it?
Edited: 07/09/2008 13:40
Reason: (Edited by mem)
Delete Edit Quote
 
xgstq
Donator
Avatar

Posts: 131
Contributes: 110

Gender: _MALE_
Online: No
Date: 07/09/2008 13:37
Re: -! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11621
doesn't look healthy...
Delete Edit Quote
 
hyperlink
Junior Member
Avatar

Posts: 92
Contributes: 3

Gender: _MALE_
Online: No
Date: 07/09/2008 13:38
Re: -! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11623
i guest you can disable uploads/media
till memht come
Delete Edit Quote
 
mem
MemHT's Dad
Admin & Developer

Avatar

Posts: 5137
Contributes: 2480

Gender: _MALE_
Online: No
Date: 07/09/2008 13:48
Re: -! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11625
How to fix:

Open inc/inc_statistics.php

Find
code
$visitorInfo['resolution'] = $_COOKIE['stats_res'];

row 123

Replace with
code
$visitorInfo['resolution'] = preg_replace('`[^0-9x]`is','',$_COOKIE['stats_res']);
Delete Edit Quote
 
mem
MemHT's Dad
Admin & Developer

Avatar

Posts: 5137
Contributes: 2480

Gender: _MALE_
Online: No
Date: 07/09/2008 13:54
Re: -! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11626
Thanks mcmxtr
Delete Edit Quote
 
xgstq
Donator
Avatar

Posts: 131
Contributes: 110

Gender: _MALE_
Online: No
Date: 07/09/2008 14:08
Re: -! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11629
Quick fix, thanks mem
Delete Edit Quote
 
mcmxtr
Just arrived
Avatar

Posts: 2
Contributes: 2

Gender: _NEUTRAL_
Online: No
Date: 07/09/2008 23:39
Re: -! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11661
thans mem.
i love it =)
Delete Edit Quote
 
Beatle
Junior Member
Avatar

Posts: 20
Contributes: 20

Gender: _MALE_
Online: No
Date: 09/09/2008 00:46
Re: -! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11741
Thanks! A friend of mine just sent me a link to milw0rm where it shows the exploit, I immediately came here to get a fix for it or to let you know about it! Glad you already had it covered!

Thanks, great script!
Delete Edit Quote
 
freaky
Crazy Member
Avatar

Posts: 635
Contributes: 487

Gender: _MALE_
Online: No
Date: 09/09/2008 10:50
Re: -! ???? MemHT Portal <= 3.9.0 Remote Create Shell Exploit -!
#post11753
quote
Beatle:
Thanks! A friend of mine just sent me a link to milw0rm where it shows the exploit, I immediately came here to get a fix for it or to let you know about it! Glad you already had it covered!

Thanks, great script!


haha I just came back from vacation and rushed on my computer at work to post this exploit.
Found it and milw0rm too Smile!!
glade it was posted before me Smile

Peace Freaky
"Don't Talk about It, Be about it! PEACE" - Mos Def

vote -- here
View Image resized (Original file: 468x60)
Thumb
Delete Edit Quote
 
Reply
Tags Cloud
Advertising
News Archive
Language
Help MemHT Portal
Navigator
Users Block
Hi Guest
IP: 38.103.63.59

Username
Password
New files
MemHT Wiki
Friends
MemHT Portal is a free software released under the GNU/GPL License by Miltenovik Manojlo