[<prev] [next>] [day] [month] [year] [list]
Message-ID: <875432850907270846u79177b45kbe88b14d44e37601@mail.gmail.com>
Date: Mon, 27 Jul 2009 22:16:18 +0630
From: "YGN Ethical Hacker Group (http://yehg.net)" <lists@...g.net>
To: full-disclosure@...ts.grok.org.uk
Subject: GMAIL-LITE Arbitrary File Upload 0.10 <=
==============================================================================
GMAIL-LITE Arbitrary File Upload 0.10 <=
==============================================================================
Discovered by
br0, YGN Ethical Hacker Group, Myanmar
http://yehg.net ~believe in full disclosure
URL: All Gmail-Lite hosting sites which enable file uploading feature
Severity: high
Advisory URL:
http://yehg.net/lab/pr0js/view.php/gmail-lite_arbitary_file_upload
Vendor: http://gmail-lite.sf.net
Overview
==========
Gmail-Lite lets us upload our desired files when we mail to our friends.
It doesn’t even restrict files types. In this case, an attacker can upload
backdoor php scripts to the server.
There, he can run his desired shell codes to do anything he wants.
###########################################################################
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists