Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: July 14, 2009
Lauren Gerber
1
Vote
0

Don't Give The LionWiki Vulnerability A Chance To Roar At Your Computer

 

Did you know that if unscrupulous users can get inside your computer, then they are also able to gLionimage.jpget into your life? This is the harsh reality of one of the disadvantages of computers, networks and the internet. If a computer security vulnerability exists, this is exactly the opportunity that an online attacker requires in order to access your computer and perform whatever activities their hearts desire. A new vulnerability has recently been reported in LionWiki, which runs high risks of being exploited by malicious online attackers in order to access the confidential and sensitive information of victims.

LionWiki is actually a small Wiki engine that has been programmed using the programming language PHP. It is file based and only needs one file to actually work in the correct manner. It is geared for personal notebooks, online journals as well as small sized websites. It is compatible with both UNIX and Windows operating systems, including Windows 2000 which contains but is not limited to these files: 15_16wdm.sys a1base.sys, axprf.ocx, bhp001.dll BROTHER.INF as well as jetpack.exe.

The vulnerability in LionWiki has occurred due to input that is passed from the "page" parameter in index.php, which is not adequately validated and confirmed prior to being used to read files. This issue may be exploited by malicious attackers in order to access local arbitrary files, via directory traversal attacks as well as URL-encoded NULL-bytes.

In order for this WikiLion vulnerability to be exploited successfully, it will first need the "magic_quotes_gpc" to be disabled. Right now you may be wondering, what version has this vulnerability been confirmed in? This vulnerability has been confirmed in version 3.0.3. This is not the only version that has been affected; the chances are actually substantially high that other versions have also been affected.Lion.jpg

This vulnerability has been rated as moderately critical. Now for the answer to the final question that I know you are wondering, what is the solution to this vulnerability? The main solution with regards to this vulnerability is for users to go as far as editing the source code in order to ensure that the input is sufficiently proved. I would like to quote in conclusion:"When I took office, only high energy physicists had ever heard of what is called the Worldwide Web.... Now even my cat has its own page."Bill Clinton

User Comments

tarsan July 23, 2009
There's a new version for all release series which fixes the problem: lionwiki.0o.cz
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

September 3, 2010
how can i remove sdfsdf, i cannot get into windows? more..
September 3, 2010
hi here is parteek kaushal i just want to tell that smone has copied my pics with my frnd n she is abusing... more..
September 3, 2010
Hello I am new here. Im sorry if this is not the right place for this post. My name... more..
more comments..
rss
Home > Computer Security > Don't Give The LionWiki Vulnerability A Chance To Roar At Your Computer