Bugtraq mailing list archives

Eduha Meeting php shell upload Vulnerabilities


From: liz0 () bsdmail com
Date: 17 Jun 2006 20:04:33 -0000

Eduha Meeting php shell upload Vulnerabilities

Site:http://eduha.forever.kz/
Demo:http://nextlevel.astrakhan.ru/meeting/

----------------------------------------------------

Example:

http://victim/path/index.php?act=add

add photo(upload php phpshell)

Bug Video: http://www.biyosecurity.be/video/meeting.rar
-----------------------------------------------------
Credit :Liz0ziM
Website:www.biyo.tk,www.biyosecurity.be
Mail   :liz0 () bsdmail com

------------------------------------------------------

Source:
http://www.blogcu.com/Liz0ziM/716541/
http://biyosecurity.be/bugs/meeting.txt
http://liz0zim.no-ip.org/meeting.txt


Current thread: