Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
a path disclosure and a posibility file inclusion and vulneability in thepeak file upload v1.3 Oct 15 2004 09:21AM
keitel andres ortega (justint rdmail net)


Justin_T

#NT - Undernet

justint (at) orangemail.com (dot) do [email concealed]

hi,

there is a posiblity path disclosure and run commands on a server usint thepeak File Upload v1.3

searching for /fileupload/index.php an attacker can upload a malicious jpg of gif and can execute commands or make a file inclusion,

but it...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus