OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Eduha Meeting php shell upload Vulnerabilities

liz0bsdmail.com
Date: Sat Jun 17 2006 - 15:04:33 CDT


Eduha Meeting php shell upload Vulnerabilities

Site:http://eduha.forever.kz/
Demo:http://nextlevel.astrakhan.ru/meeting/

----------------------------------------------------

Example:

http://victim/path/index.php?act=add

add photo(upload php phpshell)

Bug Video: http://www.biyosecurity.be/video/meeting.rar
-----------------------------------------------------
Credit :Liz0ziM
Website:www.biyo.tk,www.biyosecurity.be
Mail :liz0bsdmail.com

------------------------------------------------------

Source:
http://www.blogcu.com/Liz0ziM/716541/
http://biyosecurity.be/bugs/meeting.txt
http://liz0zim.no-ip.org/meeting.txt