hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

qcred11
QUOTE


A bug has encountred in Geeklog 1.39 possibly other versions. Default
Installation May Disclose Installation Files to Remote Users , exactly
in script install located in /admin/install.

A remote user can execute install script with permissions admin, the
directory containing the installation script is accessible to remote
users. The script itself can be executed.

example : xploit:

http://www.vulnerable.com/admin/install/install.php
http://www.vulnerable.com/install/install.php

Solution:

Delete the script after the installation.

Paul
Googled an vuln site, gonna test it now, thnx ^^
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.