BugTraq
AzzCoder => PNphpBB (Latest) Remote File Include Sep 18 2006 03:28AM
azzcoder hotmail com (1 replies)
Re: AzzCoder => PNphpBB (Latest) Remote File Include Sep 20 2006 09:12PM
Carsten Eilers (ceilers-lists gmx de) (1 replies)
Re: AzzCoder => PNphpBB (Latest) Remote File Include Sep 21 2006 04:16PM
str0ke (str0ke milw0rm com)
Carsten,

The vulnerability is in version 1.2g and below.

Source code :
http://prdownloads.sourceforge.net/pnphpbb2/

Vulnerability:
<?php
/***********************************************************************
****
* functions_admin.php
* -------------------
* begin : Saturday, Feb 13, 2001
* copyright : (C) 2001 The phpBB Group
* email : support (at) phpbb (dot) com [email concealed]
*
* $Id: functions_admin.php,v 1.2 2004/08/29 21:59:05 carls Exp $
*
*
************************************************************************
***/

/***********************************************************************
****
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
*
************************************************************************
***/
// Begin PNphpBB2 Categories Hierarchie Mod
include_once( $phpbb_root_path . 'includes/functions.' . $phpEx );

Best Regards,
/str0ke

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus