AOH :: HP Unsorted C :: B06-5295.HTM

Comdev One Admin 4.1 Remote File Inclusion



Comdev One Admin 4.1 Remote File Inclusion
Comdev One Admin 4.1 Remote File Inclusion



/****************************************/

http://www.w4cking.com 

CREDIT:
w4ck1ng.com

PRODUCT:
Comdev One Admin 4.1
http://www.comdevweb.com/oneadmin.php 

VULNERABILITY:
Remote File Inclusion

NOTES:
- requires register globals on
- requires magic quotes off

POC:
//oneadmin/adminfoot.php?path[docroot]=

ADVISORY & EXPLOIT (requires registration):
http://w4ck1ng.com/board/showthread.php?t=1491 

/****************************************/

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.