Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ImageVue Multiple Vulnerabilities

The following examples were provided:

1) check folder permissions:
http://www.example.com/dir.php
An XML-document is shown containing all folders and their permissions.
2) upload a file to a folder from the XML
http://www.example.com/admin/upload.php?path=../[foldername]
Now you're ready to upload any file.

Other vulnerabilities:
1) view dir listings
http://www.example.com/readfolder.php?path=[path]&ext=[extension]
2) querystring is passed to style and body
http://www.example.com/index.php?bgcol=[input]







 

Privacy Statement
Copyright 2009, SecurityFocus