[] NeoSense

Ourspace 2.0.9 - 'uploadmedia.cgi' Arbitrary File Upload

Author: Don
type: webapps
platform: cgi
port: 
date_added: 2007-08-29 
date_updated:  
verified: 1 
codes: OSVDB-36841;CVE-2007-4647 
tags: 
aliases:  
screenshot_url:  
application_url: 

++++++++++++++++++++++++++++++++++++
| Discovered by Breaker_unit & Don |
| Ourspace 2.0.9|
script info: http://www.codedworld.com/download/our-space/26931.html

Exploit: /cgi-bin/ourspace/newswire/uploadmedia.cgi
dork: inurl:"/cgi-bin/ourspace/

Greetz to:
Balcan Crew Members
h4cky0u.org
and my friends: str0ke & kw3rLn
+++++++++++++++++++++++++++++++++++++++

# milw0rm.com [2007-08-30]