lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060525083956.2078.qmail@web34304.mail.mud.yahoo.com> Date: Thu May 25 15:35:51 2006 From: saiedhackeriran at yahoo.com (saied hackeriran) Subject: New problem in Upload section in ASP service In The Name Of God Group:HackeranShiraz Discoverer:SaiedHacker */#######>>>>> This problem causes errors in ASP service This Problem is because of not checking the input data Well in uploading image files section When the user choosing an image file in uploading section It?s possible to pass the checking input data by injecting some Charectors and we can easily cause the system */#######>>>>> Exploit: In the uploading field we can type this code: C:\>.jpg Then press the upload button Web:http://www.SaiedHackerPro.PersianBlog.com E-mail:SaiedHackerIran@...oo.com --------------------------------- Do you Yahoo!? Get on board. You're invited to try the new Yahoo! Mail Beta. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060525/7039b249/attachment.html