Tizag Countdown Creator .v.3 Insecure Upload Vulnerability

2008-12-05 21:00:48

****(remote file upload)****

script: tizag-countdown_Version_3

***************************************************************************
download from:http://www.tizag.com/downloads/tizag-countdown_Version_3.zip

***************************************************************************
www.site.com/path/index.php (upload file.php)

shell= www.site.com/path/pics/file.php

***************************************************


Author: ahmadbady

my mail: [email protected]

***************************************************

#

Fixes

No fixes

In order to submit a new fix you need to be registered.