AOH :: HP Unsorted H :: B06-2117.HTM

Hackmaster group dmcounter remote file include
Hackmaster Group DMCounter Remote File Include
Hackmaster Group DMCounter Remote File Include

Script: DMCounter
Version: 0.9.2-b
Language: PHP
Problem: Remote File Include
Vendor: http://Www.HackMaster.Us
Discovered by: C-W-M(at)hackmaster(dot)us
Statistics software based on PHP which does not require any database
support but just uses flat files. Daily + monthly visits, which pages, from
where, browsers and OSs are listed and visually presented

A remote user can supply a specially crafted URL to cause the target
system to include and execute arbitrary PHP code from a remote
location. A remote user can execute arbitrary PHP code and operating
system commands on the target system with the privileges of the
target web service.

The vulnerable file is kopf.php


C-W-M - http://Www.HackMaster.Us

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH
We do not send spam. If you have received spam bearing an email address, please forward it with full headers to