Xtreme Scripts Download Manager 多个PHP远程文件包含漏洞

漏洞信息详情

Xtreme Scripts Download Manager 多个PHP远程文件包含漏洞

漏洞简介

Xtreme Scripts Download Manager (Xtreme Downloads) 1.0存在多个PHP远程文件包含漏洞,远程攻击者可通过在(1)download.php,(2)manager.php,(3)admin/scripts/category.php,(4)includes/add_allow.php,(5)admin/index.php和(6)admin/admin/login.php内的root参数中的URL来执行任意PHP代码。

漏洞公告

参考网址

来源: XF

名称: xtremedownloads-root-file-include(26961)

链接:http://xforce.iss.net/xforce/xfdb/26961

来源: BUGTRAQ

名称: 20060605 Multiple file include exploits in Xtreme Downloads v.1.0

链接:http://www.securityfocus.com/archive/1/archive/1/436107/100/0/threaded

来源: BUGTRAQ

名称: 20060605 file include in Xtreme Downloads v.1.0

链接:http://www.securityfocus.com/archive/1/archive/1/436104/100/0/threaded

来源: OSVDB

名称: 26646

链接:http://www.osvdb.org/26646

来源: OSVDB

名称: 26645

链接:http://www.osvdb.org/26645

来源: OSVDB

名称: 26644

链接:http://www.osvdb.org/26644

来源: OSVDB

名称: 26643

链接:http://www.osvdb.org/26643

来源: OSVDB

名称: 26648

链接:http://www.osvdb.org/26648

来源: OSVDB

名称: 26647

链接:http://www.osvdb.org/26647

来源: SREASON

名称: 1072

链接:http://securityreason.com/securityalert/1072

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享