==============================================================================
GMAIL-LITE Arbitrary File Upload 0.10 <=
==============================================================================

Discovered by 
br0, YGN Ethical Hacker Group, Myanmar 
http://yehg.net ~believe in full disclosure

URL: All Gmail-Lite hosting sites which enable file uploading feature
Vulnerability Type: SHELL CODE EXECUTION 
Severity: high

Advisory URL:
http://yehg.net/lab/pr0js/view.php/gmail-lite_arbitary_file_upload

Vendor: http://gmail-lite.sf.net


Overview
==========
Gmail-Lite lets us upload our desired files when we mail to our friends. 
It doesn’t even restrict files types. In this case, an attacker can upload backdoor php scripts to the server. 
There, he can run his desired shell codes to do anything he wants.

###########################################################################




