vendor:
Xero Portal v1.2
by:
MackRulZ
N/A
CVSS
N/A
Remote File Include
CWE
Product Name: Xero Portal v1.2
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Drunken:Golem Gaming Portal (root_path) Remote File Include Exploit
This exploit allows an attacker to remotely include a file in the Drunken:Golem Gaming Portal, version 1.2. By manipulating the 'root_path' parameter in the 'phpIRC.php' script, an attacker can execute arbitrary code on the target system. The exploit uses a shell located at 'http://pang0.by.ru/shall/pang057.zz' to execute commands.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the Drunken:Golem Gaming Portal script that addresses this issue. Additionally, proper input validation and sanitization should be implemented to prevent remote file inclusion attacks.