Battle Blog 1.25 - 'uploadform.asp' Arbitrary File Upload



EKU-ID: 16456 CVE: OSVDB-54374;CVE-2009-1609 OSVDB-ID:
Author: Cyber-Zone Published: 2009-05-08 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


         ***********************************************************************
         *  Battle Blog 1.25 (uploadform.asp) Remote File Upload Vulnerability *
         ***********************************************************************


         Found By : Cyber-Zone (ABDELKHALEK)



         +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
         http://localhost/blog/admin/uploadform.asp

         After You Upload Your File You Will See The Link To THE File Just Below



         some demos :+

         http://www.xxx.com/admin/uploadform.asp





         Have Nice Day                                             //Cyber-Zone
         +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

# milw0rm.com [2009-05-08]