Bug: Ppim <= 1.0 (upload/change password) Multiple Vulnerabilities (WLB-2008100113 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Ppim <= 1.0 (upload/change password) Multiple Vulnerabilities
 Credit: Stack
 Date: 2008.10.07
 CWE: CWE-287 (Show similar)
 CVE: CVE-2008-4427 (Show details)
CVE-2008-4428 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

Ppim <= 1.0 (upload/change password) Multiple Vulnerabilities
cript : Ppim v1.0
Download : http://scripts.ringsworld.com/organizers/ppim.zip
By Stack
Poc 1: change password
for change password go to this link
http://localhost/ppim/changepassword.php
writhe your password and confirm it

Poc 2 : upload
http://localhost/ppim/upload.php
you can upload you php shell in this link
after you go here
http://localhost/ppim/shell.php

References:

http://xforce.iss.net/xforce/xfdb/44389
http://www.securityfocus.com/bid/30627
http://www.milw0rm.com/exploits/6231
http://secunia.com/advisories/31424

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com