Bugtraq mailing list archives
Re: miniBloggie <= 1.0 (fname) Remote File Inclusion Vulnerability
From: "Carsten Eilers" <ceilers-lists () gmx de>
Date: Sun, 13 Aug 2006 14:31:44 +0200
sh3ll () sh3ll ir schrieb am Thu, 10 Aug 2006 20:38:38 +0000:
PoC: ~~~ http://www.target.com/[miniBloggie]/cls_fast_template.php?fname=[Evil Script]
Now you have your evil script included in a function. But how would you call the function, to execute your script? Regards Carsten -- Dipl.-Inform. Carsten Eilers IT-Sicherheit und Datenschutz <http://www.ceilers-it.de>
Current thread:
- miniBloggie <= 1.0 (fname) Remote File Inclusion Vulnerability sh3ll (Aug 11)
- Re: miniBloggie <= 1.0 (fname) Remote File Inclusion Vulnerability Carsten Eilers (Aug 14)