hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

qcred11
QUOTE


Vrating multiple Vulnerabilities:

1) Vrating Lets Remote Users Read and edit the files

A bug has encountred in vrating 4.01, 4.0, a remote user can view and
edit the settings.php file.

the file settings.php not have protection, so a remote user can view
file and view the
settings website including mysql host, database, username and password.

example:

http://www.vulnerable.com/admin/settings.php

2) Vrating default admin dir has not protected witch a password,
remote users can view and edit
a website configuration and access the configuration control panel.

example:

http://www.vulnerable.com/admin/

aapje
lol that is just stupid, you can just go to the /admin without a login or something and change everything
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.