Latest Security Issue can be needed for our information:

You can search for .INC files of internet using Google.

>>>>

Original Advisory:
http://blog.sitewat.ch/2010/05/phpvidz-administrative-password.html

Affecting: phpvidz 0.9.5
Vulnerability: Administrative Password Disclosure
Vendor's Homepage: http://sourceforge.net/projects/phpvidz/
Date: May 15th 2010
Researcher: Michael Brooks


phpvidz does not use a SQL database.  Instead it uses a system of flat files
to maintain application state.  The administrative password is stored within
the following file and is included during runtime.  Because this file has a
.inc extension it is viewable by the attacker.

To exploit this issue visit this url:
http://localhost/phpvidz_0.9.5/includes/init.inc
By default the password is the following constant:
define ('ADMINPASSWORD'            , '0000'                );
This password can be used to login here (A username is not required):
http://localhost/phpvidz_0.9.5/admin.php

Regards
Sandeep Thakur

-- 
You received this message because you are subscribed to the Google Groups 
"nforceit" group.
To post to this group, send an email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/nforceit?hl=en-GB.

Reply via email to