Battle Blog 1.25 - 'uploadform.asp' Arbitrary File Upload

Author: Cyber-Zone
type: webapps
platform: php
port: 
date_added: 2009-05-07  
date_updated: 2016-12-05  
verified: 1  
codes: OSVDB-54374;CVE-2009-1609  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 8647.txt  
         ***********************************************************************
         *  Battle Blog 1.25 (uploadform.asp) Remote File Upload Vulnerability *
         ***********************************************************************


         Found By : Cyber-Zone (ABDELKHALEK)



         +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
         http://localhost/blog/admin/uploadform.asp

         After You Upload Your File You Will See The Link To THE File Just Below



         some demos :+

         http://www.xxx.com/admin/uploadform.asp





         Have Nice Day                                             //Cyber-Zone
         +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

# milw0rm.com [2009-05-08]