Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15118
HistoryNov 17, 2006 - 12:00 a.m.

Hot Links download backup authorized vulnerabilities (re-post with some edit)

2006-11-1700:00:00
vulners.com
11

Hot Links is web directory system provided by mrcgiguy.com contain PHP+MySQL version and Perl version and PHP withou MySQL. All version are vulnerabilities

If admin backup database will store on server and attacker can download without authorized:
http://[domain.ext]/[path]/dlback.php?dl=fullback for PHP+MySQL ver. Perl is same above, you try it.

Contact vendor but no reply.