Full Disclosure mailing list archives
GMAIL-LITE Arbitrary File Upload 0.10 <=
From: "YGN Ethical Hacker Group (http://yehg.net)" <lists () yehg net>
Date: Mon, 27 Jul 2009 22:16:18 +0630
============================================================================== GMAIL-LITE Arbitrary File Upload 0.10 <= ============================================================================== Discovered by br0, YGN Ethical Hacker Group, Myanmar http://yehg.net ~believe in full disclosure URL: All Gmail-Lite hosting sites which enable file uploading feature Severity: high Advisory URL: http://yehg.net/lab/pr0js/view.php/gmail-lite_arbitary_file_upload Vendor: http://gmail-lite.sf.net Overview ========== Gmail-Lite lets us upload our desired files when we mail to our friends. It doesn’t even restrict files types. In this case, an attacker can upload backdoor php scripts to the server. There, he can run his desired shell codes to do anything he wants. ###########################################################################
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- GMAIL-LITE Arbitrary File Upload 0.10 <= YGN Ethical Hacker Group (http://yehg.net) (Jul 27)