J-Security Center

Title: PostNuke Trojan Horse Vulnerability

Severity: HIGH

Description:

PostNuke is a freely available web-based content management system. It is implemented in PHP and available for Unix/Linux variants as well as Microsoft Windows platforms.

It is reported that the server hosting PostNuke, www.postnuke.com, was compromised recently. Additionally, it is reported that the attacker modified the download address of the archive 'PostNuke-0.750.zip'. The new download location contained a trojaned version of the PostNuke archive.

The trojaned source transmits all data submitted into form fields during installation to a remote location. Additionally the trojaned source provides a conduit for a remote attacker to execute shell commands in the context of the web server that is hosting the trojaned code.

It is reported that users that downloaded the PostNuke archive between Sunday the 24th of Oct 2004 at 23:50 GMT and Tuesday the 26th of Oct 2004 at 8:30 GMT are likely to be affected by this vulnerability.

Affected Products:

  • PostNuke Development Team PostNuke 0.75.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.