|
ImageVue Multiple Vulnerabilities
The following examples were provided: 1) check folder permissions: http://www.example.com/dir.php An XML-document is shown containing all folders and their permissions. 2) upload a file to a folder from the XML http://www.example.com/admin/upload.php?path=../[foldername] Now you're ready to upload any file. Other vulnerabilities: 1) view dir listings http://www.example.com/readfolder.php?path=[path]&ext=[extension] 2) querystring is passed to style and body http://www.example.com/index.php?bgcol=[input] |
|
|
Privacy Statement |