about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , ImageVue Multiple Vulnerabilities


Title ImageVue Multiple Vulnerabilities
Published 2006-02-11-12:00AM
Updated 2006-02-11-12:00AM
Class Access Validation Error
CVE  
Remote  Yes
Local  No
Credit  Discovery is credited to zjieb@hotmail.com.
Vulnerable  ImageVue ImageVue 0.16.1
Not Vulnerable  
Code   The following examples were provided:

1) check folder permissions:
http://www.example.com/dir.php
An XML-document is shown containing all folders and their permissions.
2) upload a file to a folder from the XML
http://www.example.com/admin/upload.php?path=../[foldername]
Now you're ready to upload any file.

Other vulnerabilities:
1) view dir listings
http://www.example.com/readfolder.php?path=[path]&ext=[extension]
2) querystring is passed to style and body
http://www.example.com/index.php?bgcol=[input]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 20:52:14 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
dbmail Easy_Lsasr ms04-020 wwwpinkwol %2525...2F downloud a femail sex www.sexboy Sexprno My_eGaller news for c moviemasal www.englis Tamilpiche IndiaSEXWW search/exp ip board 2 news for c www.0816bc timesascen zlib php advanc CMS is Fre bvi.gongsi www.0816bc news for c Wwwcbs.com ssh 3.6 Call girls cbse resul www.joyoso www.fk6640 fashe.net Niggas news for c WWWThreads www.liveja maxcpm.inf www.315kua www.av010. Advatising Shreya news for c www.lexsen Www.Fuking news for c asp smart www.indian SSH-2. lolita fot