Bugtraq mailing list archives

phpQuiz sensitive file (install.php)


From: sn_0py () hotmail com
Date: 15 Sep 2006 11:46:07 -0000

* phpQuiz sensitive file (install.php without authentification) + Files containing interesting info (passwords for sql 
db)

* By : sn0oPy

* Risk : verry high

* Site : http://phpquiz.com/

* Dork : intitle:"phpQuiz" | " Développé par PhpQuiz v.1.0  " | "© PhpQuiz" | inurl:"PhpQuiz"

* exploit :
http://target.com/[phpquiz_path]/front/
replace by :
http://target.com/[phpquiz_path]/cfgphpquiz/install.php

* greetz : [subzero], Avg Team, Lhma9.


Current thread: