OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Phorm v3.0 Remote File Upload Vulnerability

From: security curmudgeon (jerichoattrition.org)
Date: Thu Dec 06 2007 - 20:24:20 CST


: # Phorm v3.0 Remote File Upload Vulnerability
:
: # ilker kandemir <ilkerkandemir[at]mynet.com>
:
:
: # Exploit: http://[site]/[phorm_path]/lib/fileupload.php [+]=====>> upload your shell.php
:
: # http://[site]/[phorm_path]/files/phpshell.php

This also won't work unless an administrator makes changes to
intentionally compromise the installation.

http://attrition.org/pipermail/vim/2007-July/001735.html