Topic : | Ppim <= 1.0 (upload/change password) Multiple Vulnerabilities
|
SecurityAlert : 4349
CVE : CVE-2008-4427 CVE : CVE-2008-4428 CWE : CWE-287
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Stack
Published : 07.10.2008
Affected Software : | phlatline:personal_information_manager:1.0 and previous versions |
 Advisory Content : Ppim <= 1.0 (upload/change password) Multiple Vulnerabilities
cript : Ppim v1.0
Download : http://scripts.ringsworld.com/organizers/ppim.zip
By Stack
Poc 1: change password
for change password go to this link
http://localhost/ppim/changepassword.php
writhe your password and confirm it
Poc 2 : upload
http://localhost/ppim/upload.php
you can upload you php shell in this link
after you go here
http://localhost/ppim/shell.php
References :
http://securityreason.com/expldownload/1/4478/1 (Exploit)
http://xforce.iss.net/xforce/xfdb/44389
http://www.securityfocus.com/bid/30627
http://www.milw0rm.com/exploits/6231
http://secunia.com/advisories/31424
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|