Hi people...

This went public today... there are a bug in the banner section of
php-nuke (http://www.phpnuke.org) which is web engine...

the problem is you can change the url banners form anywhere, to anywhere

example, to change the url of the first banner yo should enter un your
browser


http://target/banners.php?op=Change&bid=bannerid&url=http://where.to

if we want to change the banner number 1 to redir to www.you_are_redir we
write

http://www.foo.com/banners.php?op=Change&bid=1&url=http://you.are.redir

where www.foo.com is the server running php-nuke,

thats it...



Bye

Juan Diego

Reply via email to