Secunia Security Advisory – Toni Koivunen has discovered a vulnerability and a weakness in phpAdsNew, which can be exploited by malicious people to disclose system information and conduct SQL injection attacks. 1) Input passed to the sessionID cookie parameter in logout.php isn’t properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation requires that magic_quotes_gpc is disabled. 2) The problem is that it is possible to disclose the full path to misc/revisions/create.php by accessing it directly. This can further be exploited to list installed scripts by accessing libraries/defaults/revisions.txt. It is also possible to disclose the full path to other scripts by accessing them directly. However, this require that display_errors is enabled which is not a recommended setting for production systems. The vulnerability and the weakness have been confirmed in version 2.0.6. Other versions may also be affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/41463/sa17464.txt
Source: https://packetstormsecurity.com/files/41463/Secunia-Security-Advisory-17464.html