Ourspace 2.0.9 - 'uploadmedia.cgi' Arbitrary File Upload
Author: Don
type: webapps
platform: cgi
port:
date_added: 2007-08-29
date_updated:
verified: 1
codes: OSVDB-36841;CVE-2007-4647
tags:
aliases:
screenshot_url:
application_url:
++++++++++++++++++++++++++++++++++++
| Discovered by Breaker_unit & Don |
| Ourspace 2.0.9|
script info: http://www.codedworld.com/download/our-space/26931.html
Exploit: /cgi-bin/ourspace/newswire/uploadmedia.cgi
dork: inurl:"/cgi-bin/ourspace/
Greetz to:
Balcan Crew Members
h4cky0u.org
and my friends: str0ke & kw3rLn
+++++++++++++++++++++++++++++++++++++++
# milw0rm.com [2007-08-30]