LOGiN PANeL



«    August 2007    »
MoTuWeThFrSaSu
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
 
PoLL

1
2
3
4
5
6
7
8
9


NAViGATiON
CMS WAP Chat Blog Clones Exploits Modules Tutorials Counters Top Sites Education Templates Multimedia Guestbooks Web Search E-Commerce Forum Boards Hosting Scripts Free Templates Image Galleries Support System Ad Management WYSIWYG Editors Banner Exchange SCRiPTMAFiA.ORG
ADVERTiSiNG
Newware | Design share
TOP 10
FRiENDS
Astalavista.com – the IT News & Security community Free Video Tutorial Nulled.org Software GxIso.com WarezUN SeoMafia mp3 games pda free flash banner maker logo maker
RSS
LaST oN NULLeD.org
The Firm (2009) DVDrip Xvid The Firm (2009) DVDrip Xvid-DEFiANCE Language: English 86 Min | 640 x 360 | XviD - 1165Kbps | ...
The Littlest Angel 2011 720p BluRay x264 The Littlest Angel 2011 720p BluRay x264-BestHD | 2.23GB Language: English 01hr 24mn | 1280x720 | ...
Photoshop in Architectural Graphics Photoshop in Architectural Graphics Publisher: Sp,,ger V..nna Arch..ecture | 2009 | ISBN: ...
The Losers (2010) DVDrip Xvid The Losers (2010) DVDrip Xvid-DEFiANCE Language: English 96 Min | 640 x 360 | XviD - 1198Kbps | ...
The Three Musketeers (2011) BRRip AC3 XviD The Three Musketeers (2011) BRRip AC3 XviD-RLF Language: English 110 Min | 688 x 288 | XviD - ...


Get KVM vServers with any OS

Last questions on ask.SCRiPTMAFiA.ORG

Answered: Skadate 9 Available
Hello,   visit here for further details   http://need-help.org/17629/skdate-9-upgrade-mobile-edition
Answered: BMP.IM - 3 LETTER DOMAIN FOR SALE - CHEAP - 35$
Nice domain! If it only were BPM (Beats per Minute) though ... :D
Godaddy Coupon Code: Feb 2012
Godaddy Coupon Code: Feb 2012 Save 30% No Minimum at Godaddy. Coupon Code: gdx215b Coupon expires Sunday, February 12, 2012 at midnight (Mountain Time). Godaddy Discount – 30% Off For Your ...
.Com's Just for $2.95, register via this link (just bought 3 names)
.Com's Just for $2.95, register via this link. http://www.godaddy.com/search/domains.aspx?isc=gtnftu03
Answered: which is the best hosting for dedicated server ?
I suggest   Thewebpole.com  . Here i found a six plans with good features.you can choose any of them..Here you can host your site at cheap price.

Category: ---

/////-------------------------------------------------------///
// Uploaded by Xtreme @ Scriptmafia.org ///
//--------Xtreme-Web.net------------------------- ///
/////-------------------------------------------------------///
/////----------------SCRIPT INFO.......---------------------------------------///

File Size:1.1 MB
Latest Release:12th July, 2007
Version:1.4.7
Price: $90.00
Demo Details
Demo Url: http://demos.kubelabs.com/kubelance/

Admin Url: http://demos.kubelabs.com/kubelance/adm/
Admin User: demo
Admin Pass: demo

/////-----------------------END SCRIPT INFO--------------------------------///
Create a site where buyers can post projects/jobs and providers can bid on them. You charge a fee for each project/job created.

Feature List

Easy to edit html template files
Simple wizard installation
Charge a fee for each project and job
Plugin payment system (allows for additional payment methods to be installed easily)
Supports Paypal and NoChex
Easy to edit language files
No need to setup a cronjob
Powerful Admin panel for controlling your site
1 year of upgrades

/////----------------------END DESCRIPTION----------------------------------///
/////--------------END ALL----------------------------------------------------------///

Download Post Comment [5]


Category: Exploits

Vendor Site: http://ugamela.com
Download: http://itablackhawk.altervista.org/ogameclone.rar <- do copy/paste with this link otherwise the system will give you a 404 error
Type: Login Bypass
Severity: Hight
Patch: You can patch all manually by reading the last part of the advisory


Vuln Explanation:

The authentication check of this script doesn't work properly:

//checkeamos que el usuario este logueado y que tenga los permisos de admin
if(!check_user()){ header("Location: ./../login.php"); }
if($user['authlevel']!="3"&&$user['authlevel']!="1"){ header("Location: ../login.php");}


the use of the header function do not stop the execution of the code, so an attacker may build a special script to send command to the site without even have a registered account.
I think that even the official site might be vulnerable, even if it is working with the 0.6 version of the script.
I'll try to contact the authors to get the last version of the script and check.
If so, you'll find it nearly on this pages. ;)


Solution: The only way to solve this problem is changing the previously lines in all admin files with this lines:

//checkeamos que el usuario este logueado y que tenga los permisos de admin
if(!check_user()){ header("Location: ./../login.php"); exit;}
if($user['authlevel']!="3"&&$user['authlevel']!="1"){ header("Location: ../login.php");exit;}

Download Post Comment [3]



Category: Multimedia

/////-------------------------------------------------------///
// Uploaded by Xtreme @ Scriptmafia.org ///
//--------Xtreme-Web.net------------------------- ///
/////-------------------------------------------------------///
/////----------------SCRIPT INFO.......---------------------------------------///

- Script Name : Rayzz - Youtube Clone Script

Youtube clone, Metacafe clone, Myspace clone, Vidilife Clone

A community style clone of youtube, myspace like profile customization, fun stuff like vidilife,
functions like metacafe, so the net result you get an all in one product which is amazing

////----------------------------------------------------------------------------------------------------------///

Download Post Comment [6]